Dynamic Role-Based Access Control for Web services using context and trust

被引:0
|
作者
Tan W. [1 ,2 ]
Xu Y. [1 ]
Zhang T. [1 ]
Wen X. [1 ]
Cui L. [1 ]
Jiang C. [2 ]
机构
[1] School of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing
[2] School of Computer and Information Technology, Shanghai Second Polytechnic University, Shanghai
关键词
Access control; Dynamic authorization assignment; Life cycle context;
D O I
10.4156/jdcta.vol5.issue7.16
中图分类号
学科分类号
摘要
Currently, the security issues of Web services are hot area in information system (IS). This research mainly discusses the key technologies of information access control focusing on following works: After analyzing the dynamic characteristic of application nature for Web services, a Dynamic Role-Based Access Control using Context and Trust model (abbreviated as CT-DRBAC) for Web services is proposed. During Web services, both the subject of invoking request and object of providing service resources are dynamic nature. So, access policies are needed to consider the dynamic nature. The proposed model has been developed and the authorization framework is discussed detail. In order to implement the dynamic trust management mechanism, a dynamic user role authorization algorithm which considers the user lifecycle contexts in the open systems is proposed and designed to meet the dynamic characteristic of subject and object effectively, and achieve intelligent and scientific user role assignments. The proposed access control module can be used in intelligent information systems to grant dynamically roles to users according to the current context.
引用
收藏
页码:121 / 127
页数:6
相关论文
共 50 条
  • [41] Extending role-based access control model with context for grid applications
    Cheng, Yanfen
    Yao, Hanbing
    DCABES 2007 PROCEEDINGS, VOLS I AND II, 2007, : 650 - 654
  • [42] Automated Verification of Role-based Access Control Security Models Recovered from Dynamic Web Applications
    Alalfi, Manar H.
    Cordy, James R.
    Dean, Thomas R.
    2012 14TH IEEE INTERNATIONAL SYMPOSIUM ON WEB SYSTEMS EVOLUTION (WSE), 2012, : 1 - 10
  • [43] A Cache Considering Role-Based Access Control and Trust in Privilege Management Infrastructure
    ZHANG Shaomin~ 1
    2. School of Computer
    Wuhan University Journal of Natural Sciences, 2006, (06) : 1827 - 1830
  • [44] Role-based Quality of Service for Web Services
    Johnsen, Frank T.
    Bloebaum, Trude H.
    Nordmoen, Jorgen H.
    2012 IEEE GLOBECOM WORKSHOPS (GC WKSHPS), 2012, : 453 - 458
  • [45] Role-Based Access Control in Retrospect
    Franqueira, Virginia N. L.
    Wieringa, Roel J.
    COMPUTER, 2012, 45 (06) : 81 - 88
  • [46] Role-based access control in DCOM
    Ahn, GJ
    JOURNAL OF SYSTEMS ARCHITECTURE, 2000, 46 (13) : 1175 - 1184
  • [47] Trust Based Privacy Preserving Access Control In Web Services Paradigm
    Bhatia, Rekha
    Singh, Manpreet
    2013 SECOND INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING, NETWORKING AND SECURITY (ADCONS 2013), 2013, : 243 - 246
  • [48] Trust-Compensation-Based Access Control Model for Web Services
    Yan Danfeng
    Sun Jing
    Zhang Liying
    Yang Fangchun
    CHINA COMMUNICATIONS, 2012, 9 (12) : 8 - 21
  • [49] Practical Role-Based Access Control
    Galante, Victoria
    INFORMATION SECURITY JOURNAL, 2009, 18 (02): : 64 - 73
  • [50] Delegation in role-based access control
    Jason Crampton
    Hemanth Khambhammettu
    International Journal of Information Security, 2008, 7 : 123 - 136