ACCONV - An Access Control Model for Conversational Web Services

被引:9
作者
Paci, Federica [1 ]
Mecella, Massimo [2 ]
Ouzzani, Mourad [3 ]
Bertino, Elisa [4 ,5 ]
机构
[1] Univ Trent, Dept Informat Engn & Comp Sci, Trento, Italy
[2] Univ Roma La Sapienza, Dipartimento Informat & Sistemist Antonio Ruberti, Rome, Italy
[3] Qatar Fdn, Qatar Comp Res Inst, Doha, Qatar
[4] CERIAS, Cyber Ctr, W Lafayette, IN USA
[5] Purdue Univ, Dept Comp Sci, W Lafayette, IN 47907 USA
基金
欧盟第七框架计划;
关键词
Security; Web services; access control; conversations;
D O I
10.1145/1993053.1993055
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With organizations increasingly depending on Web services to build complex applications, security and privacy concerns including the protection of access control policies are becoming a serious issue. Ideally, service providers would like to make sure that clients have knowledge of only portions of the access control policy relevant to their interactions to the extent to which they are entrusted by the Web service and without restricting the client's choices in terms of which operations to execute. We propose ACCONV, a novel model for access control in Web services that is suitable when interactions between the client and the Web service are conversational and long-running. The conversation-based access control model proposed in this article allows service providers to limit how much knowledge clients have about the credentials specified in their access policies. This is achieved while reducing the number of times credentials are asked from clients and minimizing the risk that clients drop out of a conversation with the Web service before reaching a final state due to the lack of necessary credentials. Clients are requested to provide credentials, and hence are entrusted with part of the Web service access control policies, only for some specific granted conversations which are decided based on: (1) a level of trust that the Web service provider has vis-a-vis the client, (2) the operation that the client is about to invoke, and (3) meaningful conversations Which represent conversations that lead to a final state from the current one. We have implemented the proposed approach in a software prototype and conducted extensive experiments to show its effectiveness.
引用
收藏
页数:33
相关论文
共 50 条
  • [41] Access control in dynamic XML-based web-services with X-RBAC
    Bhatti, R
    Joshi, JBD
    Bertino, E
    Ghafoor, A
    ICWS'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON WEB SERVICES, 2003, : 243 - 249
  • [42] DESIGN OF A SECURE ARCHITECTURE FOR CONTEXT-AWARE WEB SERVICES USING ACCESS CONTROL MECHANISM
    Charles, P. Joseph
    Kumar, S. Britto Ramesh
    2014 INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING AND INFORMATICS (IC3I), 2014, : 780 - 784
  • [43] Access control system using web services for XML messaging systems
    Kaplan, A
    Topcu, AE
    Pierce, M
    Fox, G
    IKE'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INFORMATION AND KNOWLEDGE ENGINEERING, VOLS 1 AND 2, 2003, : 207 - 211
  • [44] A Privacy Access Control Framework for Web Services Collaboration with Role Mechanisms
    Liu, Linyuan
    Huang, Zhiqiu
    Zhu, Haibin
    ADVANCED RESEARCH ON ELECTRONIC COMMERCE, WEB APPLICATION, AND COMMUNICATION, PT 2, 2011, 144 : 258 - +
  • [45] The Research of Access Process in Web Services Based on XACML
    Dai, Changying
    Gong, Wentao
    Liu, Jing
    2010 2ND INTERNATIONAL WORKSHOP ON DATABASE TECHNOLOGY AND APPLICATIONS PROCEEDINGS (DBTA), 2010,
  • [46] Towards Web Service access control
    Coetzee, M
    Eloff, JHP
    COMPUTERS & SECURITY, 2004, 23 (07) : 559 - 570
  • [47] An extended XACML model to ensure secure information access for web services
    Chou, Shih-Chien
    Huang, Chun-Hao
    JOURNAL OF SYSTEMS AND SOFTWARE, 2010, 83 (01) : 77 - 84
  • [48] Access Control for the Services Oriented Architecture
    Li, Jun
    Karp, Alan H.
    SWS'07: PROCEEDINGS OF THE 2007 ACM WORKSHOP ON SECURE WEB SERVICES, 2007, : 9 - 17
  • [49] Towards a Bridge Ontology Based Approach of Access Control for Semantic Web Services
    Hu Luokai
    Wei Xiong
    Zhao Kai
    Wang Jun
    INFORMATION-AN INTERNATIONAL INTERDISCIPLINARY JOURNAL, 2011, 14 (03): : 963 - 968
  • [50] A Big Data approach to enhance the integration of Access Control Policies for Web Services
    Alodib, Mohammed
    Malik, Zaki
    2015 IEEE/ACIS 14TH INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION SCIENCE (ICIS), 2015, : 41 - 46