DocumentCode
3331476
Title
An Access Control Model for Web-Services That Supports Delegation and Creation of Authority
Author
Mabuchi, Mitsuhiro ; Shinjo, Yasushi ; Sato, Akira ; Kato, Kazuhiko
Author_Institution
Dept. of Comput. Sci., Univ. of Tsukuba, Tsukuba
fYear
2008
fDate
13-18 April 2008
Firstpage
213
Lastpage
222
Abstract
We present a new access control model for XML Web-Services that provides users with two kinds of authorities: the authority to delegate their authorities to other users and the authority to create new authorities based on their own authorities. We developed this model by introducing capability- based access control to Web services. A capability consists of an object identifier and the list of permitted operations for that object. We map an authority of a Web-Services object to a capability of the object and express the capability as a description in Web Services Description Language (WSDL). Delegation of an authority corresponds to distribution of a capability, which is done by passing a WSDL description. Creation of a new authority corresponds to generating a restricted capability based on an original capability, which is done by stacking an object on an original object. Stacking objects also makes it possible to add new functions to existing Web-Services objects without modifying the existing objects. We demonstrate the effectiveness of the proposed model using a schedule management application, which enables a project leader to delegate his or her tasks to subordinates by comparing it with Google Calendar. We also show that the execution times of stackable objects are acceptable by comparing them with typical Internet delay.
Keywords
Web services; XML; authorisation; Google calendar; Internet delay; WSDL; Web services; XML; access control model; description language; schedule management application; stackable objects; Access control; Calendars; Computer science; Delay; Internet; Intrusion detection; Project management; Stacking; Web services; XML; Access Control; Capability; Web-Service;
fLanguage
English
Publisher
ieee
Conference_Titel
Networking, 2008. ICN 2008. Seventh International Conference on
Conference_Location
Cancun
Print_ISBN
978-0-7695-3106-9
Electronic_ISBN
978-0-7695-3106-9
Type
conf
DOI
10.1109/ICN.2008.72
Filename
4498167
Link To Document