• DocumentCode
    2400802
  • Title

    Delegation-Based Security Model for Web Services

  • Author

    She, Wei ; Thuraisingham, Bhavani ; Yen, I-Ling

  • Author_Institution
    Univ. of Texas, Dallas
  • fYear
    2007
  • fDate
    14-16 Nov. 2007
  • Firstpage
    82
  • Lastpage
    91
  • Abstract
    Web service is the emerging standard that supports the seamless interoperation between different applications. While the interoperability, flexibility and automated composition are continuously enhanced, security is still the major hurdle. In recent years, lots of studies have been conducted in web service security and various security standards have been proposed. But most of these studies and standards focus on the access control policies for individual web services and do not consider the access issues in composed services. Consider a simplest service chain wherein a user x accesses service s1, and s2, in turn, accesses service s2- The current web service security framework assumes .s1 accesses s2 based on its own privilege; thus sensitive information may be incorrectly revealed to x. A better solution is that x delegates its privilege to service s1 for this access. However, problems such as how much privilege to delegate, how to confirm cross-domain delegation, how to delegate additional privilege when needed, etc. arise. The problem becomes more complex when workflow involves many layers of services. In this paper, we propose a delegation-based security model to address all these issues. It extends the basic security models and supports flexible delegation and evaluation-based access control.
  • Keywords
    Web services; security of data; Web service security; access control policies; composed web services; cross-domain delegation; delegation-based security model; evaluation-based access control; security standards; sensitive information; Access control; Authentication; Digital signatures; Information security; Privacy; Service oriented architecture; Systems engineering and theory; USA Councils; Web services; XML;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    High Assurance Systems Engineering Symposium, 2007. HASE '07. 10th IEEE
  • Conference_Location
    Plano, TX
  • ISSN
    1530-2059
  • Print_ISBN
    978-0-7695-3043-7
  • Type

    conf

  • DOI
    10.1109/HASE.2007.76
  • Filename
    4404730