DocumentCode :
836882
Title :
Model-driven trust negotiation for Web services
Author :
Skogsrud, Halvard ; Benatallah, Boualem ; Casati, Fabio
Author_Institution :
Univ. of New South Wales, Sydney, NSW, Australia
Volume :
7
Issue :
6
fYear :
2003
Firstpage :
45
Lastpage :
52
Abstract :
Trust negotiation is an approach to access control whereby access is granted based on trust established in a negotiation between the service requester and the service provider. Trust negotiation systems avoid several problems facing traditional access control models such as DAC (discretionary access control) and MAC (mandatory access control). Another problem is that Web service providers often do not know requesters identities in advance because of the ubiquitousness of services. We describe Trust-Serv, a trust negotiation framework for Web services, which features a policy language based on state machines. It is supported by lifecycle management and automated runtime enforcement tools. Credential retrieval and validation in Trust-Serv rely on predefined Web services that provide interactions with attribute assertion authorities and public key infrastructure.
Keywords :
Internet; authorisation; formal specification; formal verification; hypermedia markup languages; Internet; Trust-Serv model-driven trust negotiation system; Web services; automated runtime enforcement tools; credential retrieval; credential validation; discretionary access control; lifecycle management tools; mandatory access control; policy language; service ubiquitousness; state machines; Access control; Authorization; Automatic generation control; Identity management systems; Information security; Markup languages; Protection; Public key; Scalability; Web services;
fLanguage :
English
Journal_Title :
Internet Computing, IEEE
Publisher :
ieee
ISSN :
1089-7801
Type :
jour
DOI :
10.1109/MIC.2003.1250583
Filename :
1250583
Link To Document :
بازگشت