DocumentCode :
561312
Title :
Toward an abstract language on top of XACML for web services security
Author :
Mourad, Azzam ; Otrok, Hadi ; Yahyaoui, Hamdi ; Baajour, Lama
Author_Institution :
Dept. of Comput. Sci. & Math., Lebanese American Univ., Beirut, Lebanon
fYear :
2011
fDate :
11-14 Dec. 2011
Firstpage :
254
Lastpage :
259
Abstract :
We introduce in this paper an abstract language on top of XACML (eXtensible Access Control Markup Language) for web services security. It is based on the automatic generation of XACML security policies from abstract XACML profile(s). Our proposed approach allows first to specify the XACML profiles, which are then translated using our intended compiler into XACML security policies. The main contributions of our approach are: (1) Describing dynamic security policies using an abstract and user friendly profile language on top of XACML, (2) generating automatically the the XACML policies and (3) separating the business and security concerns of composite web services, and hence developing them separately. Our solution address the problems related to the complexity and difficulty of specifying security policies in XACML and other standard languages. We tested the feasibility of our approach by developing the library system (LB) that is composed of several Web services and applying/realizing our approach to enforce security.
Keywords :
Web services; authorisation; hypermedia markup languages; program compilers; program interpreters; Web services security; XACML security policies; abstract XACML profile; abstract language; automatic generation; compiler; eXtensible Access Control Markup Language; library system; Business; Security; RBAC; Security Policies; Web Services Security; XACML;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Internet Technology and Secured Transactions (ICITST), 2011 International Conference for
Conference_Location :
Abu Dhabi
Print_ISBN :
978-1-4577-0884-8
Type :
conf
Filename :
6148453
Link To Document :
بازگشت