Semantics-based Access Control Approach for Web Service

被引:18
作者
He, Zhengqiu [1 ]
Wu, Lifa [1 ]
Li, Huabo [1 ]
Lai, Haiguang [1 ]
Hong, Zheng [1 ]
机构
[1] PLAUST, Inst Command Automat, Nanjing, Jiangsu, Peoples R China
关键词
web service; access control; RBAC; semantics;
D O I
10.4304/jcp.6.6.1152-1161
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Due to the open and distributed characteristics of web service, its access control becomes a challenging problem which has not been addressed properly. In this paper, we show how semantic web technologies can be used to build a flexible access control system for web service. We follow the Role-based Access Control model and extend it with credential attributes. The access control model is represented by a semantic ontology, and specific semantic rules are constructed to implement such as dynamic roles assignment, separation of duty constraints and roles hierarchy reasoning, etc. These semantic rules can be verified and executed automatically by the reasoning engine, which can simplify the definition and enhance the interoperability of the access control policies. The basic access control architecture based on the semantic proposal for web service is presented. Finally, a prototype of the system is implemented to validate the proposal.
引用
收藏
页码:1152 / 1161
页数:10
相关论文
共 29 条
  • [1] Semantics-based design for secure web services
    Bartoletti, Massimo
    Degano, Pierpaolo
    Ferrari, Gian Luigi
    Zunino, Roberto
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2008, 34 (01) : 33 - 49
  • [2] The Semantic Web - A new form of Web content that is meaningful to computers will unleash a revolution of new possibilities
    Berners-Lee, T
    Hendler, J
    Lassila, O
    [J]. SCIENTIFIC AMERICAN, 2001, 284 (05) : 34 - +
  • [3] XML-Based specification for web services document security
    Bhatti, R
    Bertino, E
    Ghafoor, A
    Joshi, JBD
    [J]. COMPUTER, 2004, 37 (04) : 41 - +
  • [4] Chae JH, 2007, LECT NOTES COMPUT SC, V4464, P162
  • [5] Cirio L, 2007, LECT NOTES COMPUT SC, V4806, P1256
  • [6] Towards Web Service access control
    Coetzee, M
    Eloff, JHP
    [J]. COMPUTERS & SECURITY, 2004, 23 (07) : 559 - 570
  • [7] Damiani E, 2004, LECT NOTES COMPUT SC, V3140, P330
  • [8] Damianou N, 2001, LECT NOTES COMPUT SC, V1995, P18
  • [9] Ferraiolo D. F., 2001, ACM Transactions on Information and Systems Security, V4, P224, DOI 10.1145/501978.501980
  • [10] Finin T, 2008, SACMAT'08: PROCEEDINGS OF THE 13TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, P73