Non-functional descriptions of web services and busi- ness rules play an important role in specification and analy- sis of the security constraints of web services. As existing approaches do not provide logic and semantic model for the web services security constraints, sharing and reason- ing over them are infeasible. The proposal builds upon the project AKT's1 work in defining a Semantic Web Constraint Interchange Format (CIF), which itself builds on the pro- posed Semantic Web Rule Language (SWRL).
The main contributions of this paper are a new ontology for representing security constraints as policy and a seman- tic policy framework for the management of the policies; we also show the possibility to integrate the business rules and non-functional descriptions into policy specification by means of converting them into Constraint Satisfaction Prob- lem (CSP) using CIF.