期刊文献+

面向Web服务的基于属性的访问控制研究 被引量:12

Study on Attribute-Based Access Control for Web Services
下载PDF
导出
摘要 Web 服务是一种新的面向服务的计算模式,由于其异构性、多域性和高度动态性,它提出了独特的安全挑战。一个关键的安全挑战就是要设计有效的访问控制机制。但目前存在的访问控制机制大多是基于身份的,存在严重的管理规模和控制粒度问题。本文提出利用基于属性的访问控制(Attribute-Based Access Control,ABAC)机制来处理 Web 服务的访问控制问题。ABAC 采用相关实体的属性进行授权决策,能解决管理规模问题,并提供细粒度的控制。另外,文中对 ABAC 进行了建模,讨论了其应用,最后还给出了一种实施框架。 Web service is a new service-oriented computing paradigm which poses the unique security challenges due to its inherent heterogeneity, multidomain characteristic and highly dynamic nature. A key challenge in Web services security is the design of effective access control schemes. However, the most of current access control systems is based authorization decisions on subject identity,occrues serious administrative scalability and control granularity problems. In this paper, an attribute-based access control (ABAC) model is presented to address these issues. ABAC grants accesses to services based on the attributes possessed by related entities, and can provide administratively scalable alterna- tive to identity-based authorization methods and provide fine-grained access control For Web services. Moreover, we develop a pattern for ABAC, discuss its application issues, and also describe the implementation architecture for the system in the end.
作者 沈海波 洪帆
出处 《计算机科学》 CSCD 北大核心 2006年第4期92-96,共5页 Computer Science
基金 湖北省自然科学基金项目(NO:2004ABA055) 湖北省教育厅重点项目(NO:D200531005)资助
关键词 WEB服务 基于属性的访问控制 RBAC SAML XACML Web services, Attribute-based access control, RBAC, SAML, XACML
  • 相关文献

参考文献13

  • 1许峰,林果园,黄皓.Web Services的访问控制研究综述[J].计算机科学,2005,32(2):1-4. 被引量:15
  • 2Bonatt P, Samarati P. A Unified Framework for Regulating Access and Information Release on the Web. Journal of Computer Security, 2002, 10(3):241~272
  • 3Li N, Mitchell J C. RT: A Role-based Trust-management Framework In:Proceedings of the DARPA Information Survivability Conference and Exposition (DISCEX), Washington, D C,April 2003
  • 4Priebe T, Fernandez E B, Mehlau J I,et al. A Pattern System for Access Control. In: Proc. 18th Annual IFIP WG 11. 3 Working Conference on Data and Application Security, Sitges, Spain, July 2004
  • 5Ferraiolo D F,Sandhu R,Gavrila S,et al. Proposed NIST standard for role-based access Control. ACM Transactions on Information and System Security (TISSEC), 2001,4 (3)
  • 6Bhatti R, Joshi J B D, Bertino K Access Control in Dynamic XML-based Web-Services with X-RBAC. In: Proceedings of the First International Conference on Web Services, Las Vegas,USA, 2003
  • 7Wonohoesodo R, Taft Z. Role Based Access Control System for Web Services. In: Proceedings of the 2004 IEEE International Conference on Services Computing (SCC'04), Shanghai, China,2004. 49~56
  • 8Bhatti R, Bertino E, Ghafoor A. A Trust-based Context-Aware Access Control Model for Web Services. In: Proceedings of the IEEE International Conference on Web Services (ICWS'04), San Diego, California, USA, 2004
  • 9OASIS Standard. Security Assertion Markup Language (SAML)V1. 1, October, 2003. http://www.oasis-open.org/committees/security/does/cs-sstc-core-01, pdf
  • 10Simple Object Access Protocol (SOAP) V1. 1. May, 2000. http://www. W3. org/TR/2000/NOTE-SOAP-20000508

二级参考文献23

  • 1Web Services Security (WS-Security) version1. 005,April 2002.http://www-106. ibm. com/developerworks/webservices/library/ws-secure/.?A
  • 2W3C Working Draft. XML Encryption Syntax and Processing,March 2002. http://www. w3. org/TR/xmldsig-core/.
  • 3W3C Recommendation. XML-Signature Syntax and Processing.2002. http://www. w3. org/TR/xmldsig-core/.
  • 4OASIS Standard. Security Assertion Markup Language,SAML1.1, Oct. 2003. http ://www. oasis-open. org/committees/security/docs/cs-sstc-core-01. pdf.
  • 5OASIS Standard. XACML 1. 0 Specification Set. Feb. 2003.http://www. oasis-open. org/committees/xacml/.
  • 6ContentGuard,Inc. eXtensible Rights Markup Language, XrML 2.0. (2001) http://www. xrml. org.
  • 7W3C Working Note. XML Key Management (XKMS 2. 0).http://www. w3. org/2001/XKMS/.
  • 8Web Services Security Core Specification Working Draft 01,20September 2002. http : //lists. oasis-open. org/archives/wss/200209/pdf00000. pdf.
  • 9W3C NOTE. SOAP Security Extensions: Digital Signature.http://www. w3. org/TR/SOAP-dsig.
  • 10Towards Securing XML Web Services. ACM Workshop on XML Security,November 22,2002,Fairfax VA,USA.

共引文献14

同被引文献80

引证文献12

二级引证文献35

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部