Title :
A flexible function menu generator for supporting access control in Web applications
Author :
Chen, Kung ; Chang, Chih-Shang
Author_Institution :
Nat. Chengchi Univ., Taipei
Abstract :
Most access control frameworks for Web application enforce the control along with the invocation of an application function. While effective for preventing unauthorized access, it also incurs certain runtime overhead and user inconvenience, for it is often possible to determine whether a particular function should be allowed without actually having to try to perform it. This paper presents a flexible function menu generator (F-menugen) that restricts user menus to functions that a user´s current access-privileges permit, and can thus support access control on the presentation tier to overcome those shortcomings. The menu structure and rules governing the functions accessible to a user are specified declaratively in an XML configuration file; the rules are based on user attributes, application-specific requirements, and certain contextual information. This scheme retains the advantages of administrative scalability that role-based access control offers, yet provides the flexibility to specify more complex restrictions without actual coding
Keywords :
Internet; XML; authorisation; F-menugen; Web application; XML configuration file; access-privilege; administrative scalability; application-specific requirement; contextual information; flexible function menu generator; role-based access control; user attribute; Access control; Authentication; Authorization; Java; Logic; Runtime; Scalability; Security; Service oriented architecture; XML;
Conference_Titel :
Cyberworlds, 2005. International Conference on
Conference_Location :
Singapore
Print_ISBN :
0-7695-2378-1