10th IEEE High Assurance Systems Engineering Symposium (HASE'07) Delegation-Based Security Model for Web Services Dallas, Texas, USA November 14-November 16 ISBN: 0-7695-3043-5
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/HASE.2007.76
Web service is the emerging standard that supports the seamless interoperation between different applications. While the interoperability, flexibility and automated composition are continuously enhanced, security is still the major hurdle. In recent years, lots of studies have been conducted in web service security and various security standards have been proposed. But most of these studies and standards focus on the access control policies for individual web services and do not consider the access issues in composed services. Consider a simplest service chain wherein a user x accesses service s_1, and s_1, in turn, accesses service s_2. The current web service security framework assumes s_1 accesses s_2 based on its own privilege; thus sensitive information may be incorrectly revealed to x. A better solution is that x delegates its privilege to service s_1 for this access. However, problems such as how much privilege to delegate, how to confirm cross-domain delegation, how to delegate additional privilege when needed, etc. arise. The problem becomes more complex when workflow involves many layers of services. In this paper, we propose a delegation-based security model to address all these issues. It extends the basic security models and supports flexible delegation and evaluation-based access control.
Citation:
Wei She, Bhavani Thuraisingham, I-Ling Yen, "Delegation-Based Security Model for Web Services," hase, pp.82-91, 10th IEEE High Assurance Systems Engineering Symposium (HASE'07), 2007 Usage of this product signifies your acceptance of the Terms of Use. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||