• DocumentCode
    2359635
  • Title

    Policy and state based secure wrapper and its application to mobile agents

  • Author

    Binun, Alexander ; Gudes, Ehud

  • Author_Institution
    Ben-Gurion Univ., Beer-Sheva, Israel
  • fYear
    2003
  • fDate
    10-12 Nov. 2003
  • Firstpage
    14
  • Lastpage
    26
  • Abstract
    Execution process in modern Web applications is usually represented as a partially ordered sequence of basic actions issued by a client (login, buy, exit, etc.; the login action usually precedes purchasing). Based on these actions, a finite automaton of fine-grained authorization checks, may be specified in a separate layer that is easily configurable for security needs of a particular application. In the Mobile case there may be two such state machines - one performing state-based authorization checks of the application execution process and the other performing such checks for the mobile agent execution process. Authorization checks of these machines may be both state-based and policy based, and the policies should distinguish between human clients and mobile agents cases. We develop the framework to specify and enforce finegrained state-based authorization checks of Web application execution, consisting of a Web browser (client) and a server. We adopt this framework to the mobile case so that state machines representing finegrained authorization checks of application and mobile agent execution are synchronized.
  • Keywords
    Internet; authorisation; finite state machines; middleware; mobile agents; Web applications; Web browser; client-server systems; finite automaton; mobile agents; state machines; state-based fine-grained authorization checks; Mobile agents;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Web Congress, 2003. Proceedings. First Latin American
  • Print_ISBN
    0-7695-2058-8
  • Type

    conf

  • DOI
    10.1109/LAWEB.2003.1250278
  • Filename
    1250278