• DocumentCode
    561342
  • Title

    A policy based access control model for web services

  • Author

    Alipour, Hadiseh Seyyed ; Sabbari, Mehdi ; Nazemi, Eslam

  • Author_Institution
    Qazvin Islamic Azad Univ., Qazvin, Iran
  • fYear
    2011
  • fDate
    11-14 Dec. 2011
  • Firstpage
    472
  • Lastpage
    477
  • Abstract
    Access control security is one of the important aspects in Service Oriented Architecture (SOA) that is considered as a challenge. This issue requires further attention and review because of the architecture´s distributed nature, its high re-usability, simple accessibility and the autonomy of logical solutions units. Since the most important way for implementing SOA is the use of web services, in this paper we propose an access control model for web services to protect services and to adopt some policies on the applications using SAML and XACML standard languages. This model is defined in terms of its authentication, authorization architecture and policy formulation. Separation of duties (SoD) is a security principle that has been used extensively to prevent conflict of interest, fraud and error control in organizations. In recent years many IT organizations have struggled to identify potential SoD violations within their IT systems. Hence we propose an approach to defining SoD policy rules in our model.
  • Keywords
    Web services; XML; authorisation; fraud; organisational aspects; service-oriented architecture; software reusability; IT organizations; IT systems; SAML standard languages; SOA; SoD policy rules; SoD violations; Web services; XACML standard languages; access control security; authentication; authorization architecture; conflict of interest; error control; fraud; logical solutions units; policy based access control model; policy formulation; security principle; separation of duty; service oriented architecture; software reusability; Access control; Authentication; Business; Service oriented architecture; Simple object access protocol; Access Control Model; Policy Rule Definition; Separation of Duty; Web Services; XACML;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Internet Technology and Secured Transactions (ICITST), 2011 International Conference for
  • Conference_Location
    Abu Dhabi
  • Print_ISBN
    978-1-4577-0884-8
  • Type

    conf

  • Filename
    6148484