• DocumentCode
    125455
  • Title

    Policy Conflict Detection in Composite Web Services with RBAC

  • Author

    Danfeng Yan ; Junlin Huang ; Yuan Tian ; Yao Zhao ; Fangchun Yang

  • Author_Institution
    State Key Lab. of Networking & Switching Technol., Beijing Univ. of Posts & Telecommun., Beijing, China
  • fYear
    2014
  • fDate
    June 27 2014-July 2 2014
  • Firstpage
    534
  • Lastpage
    541
  • Abstract
    In the Web services environment, RBAC (role-based access control) model is widely accepted as an efficient approach to manage the access control. By defining the authorization relationship between subject roles and object roles in the RBAC, authorization policies are utilized to simplify the authorization management on different Web services. But the scalability and complexity of composite Web services may cause authorization policy conflict. A new authorization policy added to the system may conflict with existing ones and result in authorization chaos and authorization leaking. And when implemented in the composite Web services, policy conflict detection would be of high cost with manually checking. That makes automatic policy conflict detection important to ensure the security of authorizations in the composited Web services. This paper analyzes the features of the authorization policy in the CWS-RBAC (RBAC for composite Web services) and presents methods of detecting policy conflict including subject role propagation conflict, object role composition conflict and context conflict. The experiment designed is to validate the efficiency of each conflict detection method.
  • Keywords
    Web services; authorisation; CWS RBAC; authorization chaos; authorization leaking; authorization management; authorization policy conflict detection; authorization relationship; composite Web service complexity; composite Web service scalability; context conflict; object role composition conflict; object roles; role-based access control; subject role propagation conflict; subject roles; Authorization; Context; Feature extraction; Servers; Web services; RBAC; Web services; policy conflict detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Web Services (ICWS), 2014 IEEE International Conference on
  • Conference_Location
    Anchorage, AK
  • Print_ISBN
    978-1-4799-5053-9
  • Type

    conf

  • DOI
    10.1109/ICWS.2014.81
  • Filename
    6928941