Back to Search
Start Over
Expressive and deployable access control in open web service applications
- Source :
- IEEE Transactions on Services Computing
- Publication Year :
- 2011
-
Abstract
- Traditional access control solutions, based on preliminary identification and authentication of the access requester, are not adequate for the context of open web service systems, where servers generally do not have prior knowledge of the requesters. The research community has acknowledged such a paradigm shift and several investigations have been carried out for new approaches to regulate access control in open dynamic settings. Typically based on logic, such approaches, while appealing for their expressiveness, result not applicable in practice, where simplicity, efficiency, and consistency with consolidated technology are crucial. The eXtensible Access Control Markup Language (XACML) has established itself as the emerging technological solution for controlling access in an interoperable and flexible way. Although supporting the most common policy representation mechanisms and having acquired a significant spread in the research community and the industry, XACML still suffers from some limitations which impact its ability to support actual requirements of open web-based systems. In this paper, we provide a simple and effective formalization of novel concepts that have to be supported for enforcing the new access control paradigm needed in open scenarios, toward the aim of providing an expressive solution actually deployable with today's technology. We illustrate how the concepts of our model can be deployed in the XACML standard by exploiting its extension points for the definition of new functions, and introducing a dialog management framework to enable access control interactions between web service clients and servers.
- Subjects :
- Information Systems and Management
Markup language
Computer Networks and Communications
Computer science
deployable access control
Interoperability
0211 other engineering and technologies
XACML
Access control
02 engineering and technology
computer.software_genre
World Wide Web
Consistency (database systems)
web services
credentials
security policy communication
Server
0202 electrical engineering, electronic engineering, information engineering
computer.programming_language
021110 strategic, defence & security studies
Authentication
business.industry
020206 networking & telecommunications
Computer Science Applications
Hardware and Architecture
Web service
business
Settore ING-INF/05 - Sistemi di Elaborazione delle Informazioni
computer
Subjects
Details
- ISSN :
- 19391374
- Database :
- OpenAIRE
- Journal :
- IEEE Transactions on Services Computing
- Accession number :
- edsair.doi.dedup.....14516e6473ad8270b375c1309366120c
- Full Text :
- https://doi.org/10.1109/TSC.2010.29