DocumentCode
430249
Title
An Access Control Model for Web Services in Business Process
Author
Liu, Peng ; Chen, Zhong
Author_Institution
Peking University, Beijing, China
fYear
2004
fDate
20-24 Sept. 2004
Firstpage
292
Lastpage
298
Abstract
Business process describes a set of services that span enterprise boundaries and are provided by enterprises that see each other as partners. Web services is widely accepted and adopted to construct business process. Web services are built in exposed environment and open to security threats. When a web service contained in a business process is authorized to illegal users, it will cause economic loss of the service provider. Although there exist some standards for security of Web services and access control for services in distributed systems are well studied, there is a lack of comprehensive approach in access control for web services, especially in business process. In this paper, an extended RBAC model, called WS-RBAC, is proposed to secure web services in business process. The model takes web services in business process as protected objects and extends the classical RBAC model. Next, The software architecture of WS-RABC is presented. This paper also presents how to specify business process in the model and the authorization constraints of WS-RBAC based on WS-Policy.
Keywords
Access control; Asia; Authorization; Companies; Computer science; Environmental economics; Information security; Protection; Software architecture; Web services;
fLanguage
English
Publisher
ieee
Conference_Titel
Web Intelligence, 2004. WI 2004. Proceedings. IEEE/WIC/ACM International Conference on
Print_ISBN
0-7695-2100-2
Type
conf
DOI
10.1109/WI.2004.10081
Filename
1410817
Link To Document