DocumentCode
125455
Title
Policy Conflict Detection in Composite Web Services with RBAC
Author
Danfeng Yan ; Junlin Huang ; Yuan Tian ; Yao Zhao ; Fangchun Yang
Author_Institution
State Key Lab. of Networking & Switching Technol., Beijing Univ. of Posts & Telecommun., Beijing, China
fYear
2014
fDate
June 27 2014-July 2 2014
Firstpage
534
Lastpage
541
Abstract
In the Web services environment, RBAC (role-based access control) model is widely accepted as an efficient approach to manage the access control. By defining the authorization relationship between subject roles and object roles in the RBAC, authorization policies are utilized to simplify the authorization management on different Web services. But the scalability and complexity of composite Web services may cause authorization policy conflict. A new authorization policy added to the system may conflict with existing ones and result in authorization chaos and authorization leaking. And when implemented in the composite Web services, policy conflict detection would be of high cost with manually checking. That makes automatic policy conflict detection important to ensure the security of authorizations in the composited Web services. This paper analyzes the features of the authorization policy in the CWS-RBAC (RBAC for composite Web services) and presents methods of detecting policy conflict including subject role propagation conflict, object role composition conflict and context conflict. The experiment designed is to validate the efficiency of each conflict detection method.
Keywords
Web services; authorisation; CWS RBAC; authorization chaos; authorization leaking; authorization management; authorization policy conflict detection; authorization relationship; composite Web service complexity; composite Web service scalability; context conflict; object role composition conflict; object roles; role-based access control; subject role propagation conflict; subject roles; Authorization; Context; Feature extraction; Servers; Web services; RBAC; Web services; policy conflict detection;
fLanguage
English
Publisher
ieee
Conference_Titel
Web Services (ICWS), 2014 IEEE International Conference on
Conference_Location
Anchorage, AK
Print_ISBN
978-1-4799-5053-9
Type
conf
DOI
10.1109/ICWS.2014.81
Filename
6928941
Link To Document