• DocumentCode
    836882
  • Title

    Model-driven trust negotiation for Web services

  • Author

    Skogsrud, Halvard ; Benatallah, Boualem ; Casati, Fabio

  • Author_Institution
    Univ. of New South Wales, Sydney, NSW, Australia
  • Volume
    7
  • Issue
    6
  • fYear
    2003
  • Firstpage
    45
  • Lastpage
    52
  • Abstract
    Trust negotiation is an approach to access control whereby access is granted based on trust established in a negotiation between the service requester and the service provider. Trust negotiation systems avoid several problems facing traditional access control models such as DAC (discretionary access control) and MAC (mandatory access control). Another problem is that Web service providers often do not know requesters identities in advance because of the ubiquitousness of services. We describe Trust-Serv, a trust negotiation framework for Web services, which features a policy language based on state machines. It is supported by lifecycle management and automated runtime enforcement tools. Credential retrieval and validation in Trust-Serv rely on predefined Web services that provide interactions with attribute assertion authorities and public key infrastructure.
  • Keywords
    Internet; authorisation; formal specification; formal verification; hypermedia markup languages; Internet; Trust-Serv model-driven trust negotiation system; Web services; automated runtime enforcement tools; credential retrieval; credential validation; discretionary access control; lifecycle management tools; mandatory access control; policy language; service ubiquitousness; state machines; Access control; Authorization; Automatic generation control; Identity management systems; Information security; Markup languages; Protection; Public key; Scalability; Web services;
  • fLanguage
    English
  • Journal_Title
    Internet Computing, IEEE
  • Publisher
    ieee
  • ISSN
    1089-7801
  • Type

    jour

  • DOI
    10.1109/MIC.2003.1250583
  • Filename
    1250583