Dynamic Role-Based Access Control for Web services using context and trust

被引:0
|
作者
Tan W. [1 ,2 ]
Xu Y. [1 ]
Zhang T. [1 ]
Wen X. [1 ]
Cui L. [1 ]
Jiang C. [2 ]
机构
[1] School of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing
[2] School of Computer and Information Technology, Shanghai Second Polytechnic University, Shanghai
关键词
Access control; Dynamic authorization assignment; Life cycle context;
D O I
10.4156/jdcta.vol5.issue7.16
中图分类号
学科分类号
摘要
Currently, the security issues of Web services are hot area in information system (IS). This research mainly discusses the key technologies of information access control focusing on following works: After analyzing the dynamic characteristic of application nature for Web services, a Dynamic Role-Based Access Control using Context and Trust model (abbreviated as CT-DRBAC) for Web services is proposed. During Web services, both the subject of invoking request and object of providing service resources are dynamic nature. So, access policies are needed to consider the dynamic nature. The proposed model has been developed and the authorization framework is discussed detail. In order to implement the dynamic trust management mechanism, a dynamic user role authorization algorithm which considers the user lifecycle contexts in the open systems is proposed and designed to meet the dynamic characteristic of subject and object effectively, and achieve intelligent and scientific user role assignments. The proposed access control module can be used in intelligent information systems to grant dynamically roles to users according to the current context.
引用
收藏
页码:121 / 127
页数:6
相关论文
共 50 条
  • [1] Role-based access control for web services
    College of Information Sciences and Technology, Donghua University, 1882 Yan'an Road , Shanghai 200051, China
    WSEAS Trans. Inf. Sci. Appl., 2006, 8 (1553-1558):
  • [2] A context-aware role-based access control model for Web services
    Shen, HB
    Hong, F
    ICEBE 2005: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2005, : 220 - 223
  • [3] Context-aware role-based access control model for Web services
    Feng, X
    Jun, M
    Hao, H
    Li, X
    GRID AND COOPERATIVE COMPUTING GCC 2004 WORKSHOPS, PROCEEDINGS, 2004, 3252 : 430 - 436
  • [4] Role-based access control system for web services
    Feng, X
    Guoyuan, L
    Hao, H
    Li, X
    FOURTH INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY, PROCEEDINGS, 2004, : 357 - 362
  • [5] An extended role-based access control for Web services
    Zhu, Yi-qun
    Li, Jian-hua
    Zhang, Quan-hai
    SECRYPT 2006: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2006, : 471 - +
  • [6] A model for context-dependent access control for web-based services with role-based approach
    Wolf, R
    Keinz, T
    Schneider, M
    14TH INTERNATIONAL WORKSHOP ON DATABASE AND EXPERT SYSTEMS APPLICATIONS, PROCEEDINGS, 2003, : 209 - 214
  • [7] Role-based access control on the web using LDAP
    Park, JS
    Ahn, GJ
    Sandhu, R
    DATABASE AND APPLICATION SECURITY XV, 2002, 87 : 19 - 30
  • [8] Role-based access control on the web using Java']Java™
    Giuri, L
    FOURTH ACM WORKSHOP ON ROLE-BASED ACCESS CONTROL, PROCEEDINGS, 1999, : 11 - 18
  • [9] The implementation of role-based access control on the web
    Xu, CG
    Yan, H
    Liu, FG
    2001 INTERNATIONAL CONFERENCES ON INFO-TECH AND INFO-NET PROCEEDINGS, CONFERENCE A-G: INFO-TECH & INFO-NET: A KEY TO BETTER LIFE, 2001, : D251 - D255
  • [10] Spatial context in role-based access control
    Zhang, Hong
    He, Yeping
    Shi, Zhiguo
    INFORMATION SECURITY AND CRYPTOLOGY - ICISC 2006, PROCEEDINGS, 2006, 4296 : 166 - 178