BOOKS
BOOK SERIES
JOURNALS
PROCEEDINGS
TEACHING CASES
PAY-PER-VIEW
REFERENCE
E-RESOURCES
ABOUT IGI
BECOME AN AUTHOR/EDITOR  |   MAILING LIST  |   HOW TO ORDER  |   LIBRARY SUGGESTION | EXAMINATION REQUESTS/COURSE ADOPTION | DISTRIBUTORS
IGI Online Bookstore
Click here to PLAY Demo Click here to Start Search Search 30,000+ chapters, articles, and cases - available for download today!

IGI Global Online Symposium!



  Browse Our Bookstore
IGI Catalogs & Newsletters
Forthcoming Titles
Featured Book
By Category
Advanced Search

  Shop
My Profile
View My Cart

  Contact Us
IGI Global
Main Office
701 E. Chocolate Avenue
Hershey, PA 17033, USA
Tel: 717-533-8845 x100
Toll Free: 1-866-342-6657
Fax: 717-533-8661
    or 717-533-7115
 

An Adaptive Access Control Model for Web Services:
Our Price:    $30.00 US
Article #:    ITJ3332
Pages:    27 - 60
Source:    International Journal of Web Services Research, Vol. 3, Issue 3
Author(s):    Bertino, Elisa; Squicciarini, Anna C.; Martino, Lorenzo; Paci, Federica
Affiliation(s):    Purdue University, USA; Purdue University, USA; Purdue University, USA; University of Milano, Italy

Order Now! This document will be delivered electronically. Terms of Delivery
 

Description
This paper presents an innovative access control model, referred to as Web service Access Control Version 1 (Ws-AC1), specifically tailored to Web services. The most distinguishing features of this model are the flexible granularity in protection objects and negotiation capabilities. Under Ws-AC1, an authorization can be associated with a single service and can specify for which parameter values the service can be authorized for use, thus providing a fine access control granularity. Ws-AC1 also supports coarse granularities in protection objects in that it provides the notion of service class under which several services can be grouped. Authorizations can then be associated with a service class and automatically propagated to each element in the class. The negotiation capabilities of Ws-AC1 are related to the negotiation of identity attributes and the service parameters. Identity attributes refer to information that a party requesting a service may need to submit in order to obtain the service. The access control policy model of Ws-AC1 supports the specification of policies in which conditions are stated, specifying the identity attributes to be provided and constraints on their values. In addition, conditions may also be specified against context parameters, such as time. To enhance privacy and security, the actual submission of these identity attributes is executed through a negotiation process. Parameters may also be negotiated when a subject requires use of a service with certain parameters values that, however, are not authorized under the policies in place. In this paper, we provide the formal definitions underlying our model and the relevant algorithms, such as the access control algorithm. We also present an encoding of our model in the Web Services Description Language (WSDL) standard for which we develop an extension, required to support Ws-AC1.

 
Books  |  Book Series  |  Journals  |  Proceedings  |  Teaching Cases  |  Pay-Per-View  |  Reference  |  E-Resources  |  About IGI
Become An Author/Editor  |  Mailing List  |  How To Order  |  Library Suggestion  |  Examination Requests

IGI Global - All Rights Reserved ©2001-2010