• DocumentCode
    1840129
  • Title

    Workflow-Based Dynamic Access Control in a Service-Oriented Architecture

  • Author

    Hwang, Gwan-Hwan ; Wu-Lee, Chi ; Jiang, Zhong-Xiang

  • Author_Institution
    Dept. of Comput. Sci. & Inf. Eng., Nat. Taiwan Normal Univ., Taipei, Taiwan
  • fYear
    2012
  • fDate
    26-29 March 2012
  • Firstpage
    47
  • Lastpage
    52
  • Abstract
    In this paper we propose a novel access control model called workflow-based dynamic access control (WBDAC) for SOA and workflow-based systems. Besides regulating the access control according to the dynamic behavior of workflow processes, the WBDAC is based on the idea of creating transient policies dynamically so as to alleviate the role- and rule-explosion problems in RBAC and ABAC. We define a logical expression language of WBDAC called the dynamic access control language for an SOA (DACL4SOA). We have also designed an architecture to support the DACL4SOA in SOA systems based on the Business Process Execution Language and the Extensible Access Control Markup Language. The presented implementation and experimental results demonstrate the feasibility of the proposed model.
  • Keywords
    XML; authorisation; business data processing; service-oriented architecture; workflow management software; ABAC; DACL4SOA; RBAC; WBDAC; attribute-based access control; business process execution language; dynamic access control language; extensible access control markup language; logical expression language; role-and rule-explosion problems; role-based access control; service-oriented architecture; workflow process dynamic behavior; workflow-based dynamic access control; workflow-based systems; Access control; Personnel; Process control; Service oriented architecture; Transient analysis; Access Control Model; BPEL; SOA; Web Services; Workflow;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications Workshops (WAINA), 2012 26th International Conference on
  • Conference_Location
    Fukuoka
  • Print_ISBN
    978-1-4673-0867-0
  • Type

    conf

  • DOI
    10.1109/WAINA.2012.65
  • Filename
    6185098