• DocumentCode
    3127510
  • Title

    A Policy-Based Authorization Framework for Web Services: Integrating XGTRBAC and WS-Policy

  • Author

    Bhatti, Rafae ; Sanz, Daniel ; Bertino, Elisa ; Ghafoor, Arif

  • Author_Institution
    IBM, San Jose
  • fYear
    2007
  • fDate
    9-13 July 2007
  • Firstpage
    447
  • Lastpage
    454
  • Abstract
    Authorization and access control in Web services is complicated by the unique requirements of the dynamic Web services paradigm. Current authentication mechanisms for Web services do not differentiate between users in terms of fine-grained access privileges. This results in an all-or-nothing access which is not flexible enough for modern day business processes using Web services to execute. In this paper, we present a policy-based authorization framework to address this requirement. We have designed a profile of the well-known WS-policy specification tailored to meet the access control requirements in Web services by integrating WS-policy with an access control policy specification language, X-GTRBAC. The design of the profile is aimed at bridging the gap between available policy standards for Web services and existing policy specification languages for access control. The profile supports the WS-policy attachment specification, which allows separate policies to be associated with multiple components of a Web service description, and one of our key contributions is the design of an algorithm to compute the effective policy for the Web service given the multiple policy attachments. To allow Web service applications to use our solution, we have adopted a component-based design approach based on well-known UML notations. We have also prototyped our architecture, and implemented it as a loosely coupled Web service providing healthcare information services to physicians subject to applicable authorization policies.
  • Keywords
    Unified Modeling Language; Web services; authorisation; formal specification; object-oriented programming; UML; WS-policy specification; Web services; X-GTRBAC; access control; authentication mechanisms; component-based design; policy-based authorization framework; Access control; Algorithm design and analysis; Authentication; Authorization; Computer architecture; Prototypes; Service oriented architecture; Specification languages; Unified modeling language; Web services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Web Services, 2007. ICWS 2007. IEEE International Conference on
  • Conference_Location
    Salt Lake City, UT
  • Print_ISBN
    0-7695-2924-0
  • Type

    conf

  • DOI
    10.1109/ICWS.2007.10
  • Filename
    4279630