Web Service Authorization framework

被引:1
作者
Ziebermayr, T [1 ]
Probst, S [1 ]
机构
[1] Software Competence Ctr Hagenberg, A-4232 Hagenberg, Austria
来源
IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS | 2004年
关键词
web service; authorization; security; service; framework;
D O I
10.1109/ICWS.2004.1314789
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Web Services represent an important technology for distributed applications and will replace various other technologies for distributed application development soon. A lot of problems of the early days of Web Services are solved now. However, for authorization no appropriate solution is available and ready to use. We define requirements for authorization of Web Services and investigate existing authorization solutions concerning these requirements. Based on existing authorization solutions and the defined requirements, a Web Service Authorization framework is developed. We describe concepts and the design of the proposed framework and give an, overview of selected implementation aspects (e.g. authorization data access, descriptive deployment). The framework emphasizes easy deployment of Web Service authorization and is ready to use. Practical experience using the framework concludes the paper.
引用
收藏
页码:614 / 621
页数:8
相关论文
共 20 条
  • [1] *AP WEB SERV, 2003, AXIS
  • [2] Chaudhri AB, 2003, XML DATA MANAGEMENT
  • [3] Role-Based Access Controls: Status, Dissemination, and Prospects for Generic Security Mechanisms
    Wolfgang Essmayr
    Stefan Probst
    Edgar Weippl
    [J]. Electronic Commerce Research, 2004, 4 (1-2) : 127 - 156
  • [4] *FOUNDST INC, CORE SEC TECHN SEC M
  • [5] JENDROCK E, 2002, J2EE TUT
  • [6] *JIFF SOFTW, 2003, XACML IMPL
  • [7] KRAFT R, 2002, ACM WORKSH XML SEC N
  • [8] LAI C, 1999, P 15 ANN COMP SEC AP
  • [9] *OASIS, 2003, EXT ACC CONTR MARK L
  • [10] SANDHU R, 1996, ACM COMPUTING SURVEY, V28