• DocumentCode
    3331476
  • Title

    An Access Control Model for Web-Services That Supports Delegation and Creation of Authority

  • Author

    Mabuchi, Mitsuhiro ; Shinjo, Yasushi ; Sato, Akira ; Kato, Kazuhiko

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Tsukuba, Tsukuba
  • fYear
    2008
  • fDate
    13-18 April 2008
  • Firstpage
    213
  • Lastpage
    222
  • Abstract
    We present a new access control model for XML Web-Services that provides users with two kinds of authorities: the authority to delegate their authorities to other users and the authority to create new authorities based on their own authorities. We developed this model by introducing capability- based access control to Web services. A capability consists of an object identifier and the list of permitted operations for that object. We map an authority of a Web-Services object to a capability of the object and express the capability as a description in Web Services Description Language (WSDL). Delegation of an authority corresponds to distribution of a capability, which is done by passing a WSDL description. Creation of a new authority corresponds to generating a restricted capability based on an original capability, which is done by stacking an object on an original object. Stacking objects also makes it possible to add new functions to existing Web-Services objects without modifying the existing objects. We demonstrate the effectiveness of the proposed model using a schedule management application, which enables a project leader to delegate his or her tasks to subordinates by comparing it with Google Calendar. We also show that the execution times of stackable objects are acceptable by comparing them with typical Internet delay.
  • Keywords
    Web services; XML; authorisation; Google calendar; Internet delay; WSDL; Web services; XML; access control model; description language; schedule management application; stackable objects; Access control; Calendars; Computer science; Delay; Internet; Intrusion detection; Project management; Stacking; Web services; XML; Access Control; Capability; Web-Service;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Networking, 2008. ICN 2008. Seventh International Conference on
  • Conference_Location
    Cancun
  • Print_ISBN
    978-0-7695-3106-9
  • Electronic_ISBN
    978-0-7695-3106-9
  • Type

    conf

  • DOI
    10.1109/ICN.2008.72
  • Filename
    4498167