• DocumentCode
    1931493
  • Title

    A fine-grained access control model for Web services

  • Author

    Bertino, E. ; Squicciarini, A.C. ; Mevi, D.

  • Author_Institution
    Dept. of Comput. Sci., Purdue Univ., West Lafayette, IN, USA
  • fYear
    2004
  • fDate
    15-18 Sept. 2004
  • Firstpage
    33
  • Lastpage
    40
  • Abstract
    The emerging Web service technology has enabled the development of Internet-based applications that integrate distributed and heterogeneous systems and processes, which are owned by different organizations. However, while Web services are rapidly becoming a fundamental paradigm for the development of complex Web applications, several security issues still need to be addressed. Among the various open issues concerning security, an important issue is represented by the development of suitable access control models, able to restrict access to Web services to authorized users. We present an innovative access control model for Web services. The model is characterized by a number of key features, including identity attributes and service negotiation capabilities. We also discuss an architecture implementing the model and we propose the use of a certificate scheme able to support the exchange and verification of subject attributes.
  • Keywords
    Internet; XML; authorisation; certification; open systems; Internet-based applications; Web services; XML; authorization; certificate scheme; distributed systems; fine-grained access control model; heterogeneous systems; service negotiation capabilities; Access control; Web services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Services Computing, 2004. (SCC 2004). Proceedings. 2004 IEEE International Conference on
  • Print_ISBN
    0-7695-2225-4
  • Type

    conf

  • DOI
    10.1109/SCC.2004.1357987
  • Filename
    1357987