DocumentCode
836882
Title
Model-driven trust negotiation for Web services
Author
Skogsrud, Halvard ; Benatallah, Boualem ; Casati, Fabio
Author_Institution
Univ. of New South Wales, Sydney, NSW, Australia
Volume
7
Issue
6
fYear
2003
Firstpage
45
Lastpage
52
Abstract
Trust negotiation is an approach to access control whereby access is granted based on trust established in a negotiation between the service requester and the service provider. Trust negotiation systems avoid several problems facing traditional access control models such as DAC (discretionary access control) and MAC (mandatory access control). Another problem is that Web service providers often do not know requesters identities in advance because of the ubiquitousness of services. We describe Trust-Serv, a trust negotiation framework for Web services, which features a policy language based on state machines. It is supported by lifecycle management and automated runtime enforcement tools. Credential retrieval and validation in Trust-Serv rely on predefined Web services that provide interactions with attribute assertion authorities and public key infrastructure.
Keywords
Internet; authorisation; formal specification; formal verification; hypermedia markup languages; Internet; Trust-Serv model-driven trust negotiation system; Web services; automated runtime enforcement tools; credential retrieval; credential validation; discretionary access control; lifecycle management tools; mandatory access control; policy language; service ubiquitousness; state machines; Access control; Authorization; Automatic generation control; Identity management systems; Information security; Markup languages; Protection; Public key; Scalability; Web services;
fLanguage
English
Journal_Title
Internet Computing, IEEE
Publisher
ieee
ISSN
1089-7801
Type
jour
DOI
10.1109/MIC.2003.1250583
Filename
1250583
Link To Document