• DocumentCode
    3165818
  • Title

    A flexible function menu generator for supporting access control in Web applications

  • Author

    Chen, Kung ; Chang, Chih-Shang

  • Author_Institution
    Nat. Chengchi Univ., Taipei
  • fYear
    2005
  • fDate
    23-25 Nov. 2005
  • Lastpage
    530
  • Abstract
    Most access control frameworks for Web application enforce the control along with the invocation of an application function. While effective for preventing unauthorized access, it also incurs certain runtime overhead and user inconvenience, for it is often possible to determine whether a particular function should be allowed without actually having to try to perform it. This paper presents a flexible function menu generator (F-menugen) that restricts user menus to functions that a user´s current access-privileges permit, and can thus support access control on the presentation tier to overcome those shortcomings. The menu structure and rules governing the functions accessible to a user are specified declaratively in an XML configuration file; the rules are based on user attributes, application-specific requirements, and certain contextual information. This scheme retains the advantages of administrative scalability that role-based access control offers, yet provides the flexibility to specify more complex restrictions without actual coding
  • Keywords
    Internet; XML; authorisation; F-menugen; Web application; XML configuration file; access-privilege; administrative scalability; application-specific requirement; contextual information; flexible function menu generator; role-based access control; user attribute; Access control; Authentication; Authorization; Java; Logic; Runtime; Scalability; Security; Service oriented architecture; XML;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cyberworlds, 2005. International Conference on
  • Conference_Location
    Singapore
  • Print_ISBN
    0-7695-2378-1
  • Type

    conf

  • DOI
    10.1109/CW.2005.4
  • Filename
    1587590