DocumentCode :
2263312
Title :
xAccess: A unified user-centric access control framework for web applications
Author :
Singh, Kapil
Author_Institution :
IBM T.J. Watson Research Center
fYear :
2012
fDate :
16-20 April 2012
Firstpage :
530
Lastpage :
533
Abstract :
With the rapid growth of Web 2.0, users are contributing more and more content on the Internet, in the form of user profiles, blogs, reviews, etc. With this increased sharing comes a pressing need for access control policies and mechanisms to protect the users´ privacy. Access control has remained largely centralized and under the control of the web applications. Moreover, most web applications either provide no or very primitive and limited access control. We argue that the owner of any piece of data on the web should be able to decide how to control access to this data. This argument should hold not only for the web applications contributing data, but also for the contributing users. In other words, users should be able to choose their own access control models to control the sharing of their data independent of the underlying applications. In this work, we present a novel framework, called xAccess, for providing access control that empowers users to control how they want their data to be accessed. xAccess is analogous to the single sign-on mechanism, however, instead of providing login capability, it provides the user with a single point for defining his access control models and policies for one or multiple applications. On one hand, xAccess enables individual users to use a single unified access control across multiple web applications; and on the other hand, it allows an application to support different access control models deployed by its users with a single model abstraction. We demonstrate the viability of our design by means of a platform prototype. The usability of the platform is further evaluated by developing sample applications using the xAccess APIs.
Keywords :
Internet; application program interfaces; authorisation; data privacy; Internet; Web 2.0; Web applications; access control models; access control policies; data sharing control; login capability; platform prototype; single sign-on mechanism; unified user-centric access control framework; user privacy protection mechanisms; xAccess APIs; Access control; Blogs; Browsers; Data models; Encyclopedias; Internet; Servers;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network Operations and Management Symposium (NOMS), 2012 IEEE
Conference_Location :
Maui, HI
ISSN :
1542-1201
Print_ISBN :
978-1-4673-0267-8
Electronic_ISBN :
1542-1201
Type :
conf
DOI :
10.1109/NOMS.2012.6211948
Filename :
6211948
Link To Document :
بازگشت