• DocumentCode
    2388605
  • Title

    Attributed based access control (ABAC) for Web services

  • Author

    Yuan, Eric ; Tong, Jin

  • Author_Institution
    Booz Allen Hamilton Inc., McLean, VA, USA
  • fYear
    2005
  • fDate
    11-15 July 2005
  • Lastpage
    569
  • Abstract
    For companies and government agencies alike, the emergence of Web services technologies and the evolution of distributed systems toward service oriented architectures (SOA) have helped promote collaboration and information sharing by breaking down "stove-piped" systems and connecting them via loosely coupled, interoperable system-to-system interfaces. Such architectures, however, also bring about their own security challenges that require due consideration. Unfortunately, the current information security mechanisms are insufficient to address these challenges. In particular, the access control models today are mostly static and coarsely grained; they are not well-suited for the service-oriented environments where information access is dynamic and ad-hoc in nature. This paper outlines the access control challenges for Web services and SOA, and proposes an attribute based access control (ABAC) model as a new approach, which is based on subject, object, and environment attributes and supports both mandatory and discretionary access control needs. The paper describes the ABAC model in terms of its authorization architecture and policy formulation, and makes a detailed comparison between ABAC and traditional role-based models, which clearly shows the advantages of ABAC. The paper then describes how this new model can be applied to securing Web service invocations, with an implementation based on standard protocols and open-source tools. The paper concludes with a summary of the ABAC model\´s benefits and some future directions.
  • Keywords
    Internet; authorisation; open systems; user interfaces; Web services; attribute based access control; authorization architecture; information sharing; open-source tool; service oriented architectures; standard protocol; system-to-system interfaces; Access control; Authorization; Collaboration; Government; Information security; Joining processes; Open source software; Protocols; Service oriented architecture; Web services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Web Services, 2005. ICWS 2005. Proceedings. 2005 IEEE International Conference on
  • Print_ISBN
    0-7695-2409-5
  • Type

    conf

  • DOI
    10.1109/ICWS.2005.25
  • Filename
    1530847