DocumentCode :
2358720
Title :
Enforcing Context-Sensitive Policies in Collaborative Business Environments
Author :
Sardinha, Alberto ; Rao, Jinghai ; Sadeh, Norman
Author_Institution :
Carnegie Mellon Univ., Pittsburgh
fYear :
2007
fDate :
17-20 April 2007
Firstpage :
705
Lastpage :
714
Abstract :
As enterprises seek to engage in increasingly rich and agile forms of collaboration, they are turning towards service-oriented architectures that enable them to selectively expose different levels of functionality to both existing and prospective business partners. This includes enforcing access control policies whose elements are tied to changing contractual relationships or to information obtained from external sources (e.g. ratings, credit worthiness, export restrictions, etc.). To ensure maximum openness, we argue that such sources of contextual information should themselves be represented as web services that can be identified and accessed on the fly. as required to enforce relevant policies. We propose an architecture for enforcing context-sensitive access control policies in which sources of information can be annotated with rich semantic profiles. This includes a meta-control architecture for dynamically orchestrating policy reasoning together with the identification and access of external sources of information required to enforce policies. We show that this architecture can be implemented as an extension to XACML´s PIP and context handler functionality. We proceed to show that our architecture extends to a broader class of corporate and regulatory policies. The paper also presents computational experiments aimed at evaluating the scalability of our architecture.
Keywords :
Web services; authorisation; business data processing; contracts; groupware; inference mechanisms; semantic Web; software architecture; Web services; collaborative business environments; context-sensitive access control policies; contractual relationships; dynamically orchestrating policy reasoning; meta-control architecture; semantic profiles; service-oriented architectures; Access control; Collaboration; Companies; Computer architecture; Context-aware services; Information resources; Scalability; Service oriented architecture; Turning; Web services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Data Engineering Workshop, 2007 IEEE 23rd International Conference on
Conference_Location :
Istanbul
Print_ISBN :
978-1-4244-0832-0
Electronic_ISBN :
978-1-4244-0832-0
Type :
conf
DOI :
10.1109/ICDEW.2007.4401058
Filename :
4401058
Link To Document :
بازگشت