• DocumentCode
    3126554
  • Title

    An Access Control System for Web Service Compositions

  • Author

    Srivatsa, Mudhakar ; Iyengar, Arun ; Mikalsen, Thomas ; Rouvellou, Isabelle ; Yin, Jian

  • Author_Institution
    Georgia Inst. of Technol., Atlanta
  • fYear
    2007
  • fDate
    9-13 July 2007
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Service composition has emerged as a fundamental technique for developing Web applications. Multiple services, often from different organizations or trust domains, may be dynamically composed to satisfy a user´s request. Access control in the presence of service compositions is a challenging security problem. In this paper, we present an access control model and techniques for specifying and enforcing access control rules on Web service compositions. A key advantage of our approach is that past histories of service invocations can be used to make access control decisions. Our approach allows role hierarchies and separation of duty constraints. Access controls rules may be parameterized by one or more arguments. We have implemented our access control model via a declarative policy specification language which uses pure-past linear temporal logic (PPLTL). We describe an implementation of our approach using a supply chain management (SCM) application. Our experiments show that our approach can enforce expressive and flexible access control policies while incurring reasonable performance overhead on the application.
  • Keywords
    Web services; authorisation; supply chain management; temporal logic; Web service compositions; access control system; pure-past linear temporal logic; security problem; service invocations; supply chain management; Access control; Databases; Educational institutions; History; Logic; Manufacturing; Security; Specification languages; Supply chain management; Web services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Web Services, 2007. ICWS 2007. IEEE International Conference on
  • Conference_Location
    Salt Lake City, UT
  • Print_ISBN
    0-7695-2924-0
  • Type

    conf

  • DOI
    10.1109/ICWS.2007.31
  • Filename
    4279576