• DocumentCode
    2961807
  • Title

    Architecture and Protocol for User-Controlled Access Management in Web 2.0 Applications

  • Author

    Machulak, Maciej P. ; Van Moorsel, Aad

  • Author_Institution
    Centre for Cybercrime & Comput. Security, Newcastle Univ., Newcastle upon Tyne, UK
  • fYear
    2010
  • fDate
    21-25 June 2010
  • Firstpage
    62
  • Lastpage
    71
  • Abstract
    The rapidly developing Web environment provides users with a wide set of rich services as varied and complex as desktop applications. Those services are collectively referred to as ``Web 2.0´´, with examples such as Google Docs, Flickr, or Wordpress, that allow users to create, manage and share their content online. By switching from desktop applications to their cloud-based Web equivalents users release even more data online. It is the user who creates this data, who disseminates it and who shares it with other users and services. Storing and sharing resources on the Web poses new security challenges. Access control, in particular, is currently poorly addressed in such an environment and is not well suited to the increasing number of resources that are available online. We propose a new approach to access control for the Web. Our approach puts a user in full control of assigning access rights to their resources which may be spread across multiple cloud-based Web applications. Unlike existing authorization systems, it relies on a user´s centrally located security requirements for these resources.
  • Keywords
    Internet; authorisation; protocols; Flickr; Google Docs; Web 2.0 application; Web environment provide; Wordpress; access control; authorization system; cloud-based Web application; cloud-based Web equivalent; content online; data online; protocol; user-controlled access management; Adaptation model; Authorization; Permission; Proposals; Protocols; Web 2.0; access control; authorization; security; usability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Distributed Computing Systems Workshops (ICDCSW), 2010 IEEE 30th International Conference on
  • Conference_Location
    Genova
  • ISSN
    1545-0678
  • Print_ISBN
    978-1-4244-7471-4
  • Type

    conf

  • DOI
    10.1109/ICDCSW.2010.37
  • Filename
    5628738