DocumentCode
3165818
Title
A flexible function menu generator for supporting access control in Web applications
Author
Chen, Kung ; Chang, Chih-Shang
Author_Institution
Nat. Chengchi Univ., Taipei
fYear
2005
fDate
23-25 Nov. 2005
Lastpage
530
Abstract
Most access control frameworks for Web application enforce the control along with the invocation of an application function. While effective for preventing unauthorized access, it also incurs certain runtime overhead and user inconvenience, for it is often possible to determine whether a particular function should be allowed without actually having to try to perform it. This paper presents a flexible function menu generator (F-menugen) that restricts user menus to functions that a user´s current access-privileges permit, and can thus support access control on the presentation tier to overcome those shortcomings. The menu structure and rules governing the functions accessible to a user are specified declaratively in an XML configuration file; the rules are based on user attributes, application-specific requirements, and certain contextual information. This scheme retains the advantages of administrative scalability that role-based access control offers, yet provides the flexibility to specify more complex restrictions without actual coding
Keywords
Internet; XML; authorisation; F-menugen; Web application; XML configuration file; access-privilege; administrative scalability; application-specific requirement; contextual information; flexible function menu generator; role-based access control; user attribute; Access control; Authentication; Authorization; Java; Logic; Runtime; Scalability; Security; Service oriented architecture; XML;
fLanguage
English
Publisher
ieee
Conference_Titel
Cyberworlds, 2005. International Conference on
Conference_Location
Singapore
Print_ISBN
0-7695-2378-1
Type
conf
DOI
10.1109/CW.2005.4
Filename
1587590
Link To Document