A fine-grained access control model for Web services

E. Bertino, A. C. Squicciarini, D. Mevi

Research output: Chapter in Book/Report/Conference proceedingConference contribution

28 Scopus citations

Abstract

The emerging Web service technology has enabled the development of Internet-based applications that integrate distributed and heterogeneous systems and processes which are owned by different organizations. However, while Web services are rapidly becoming a fundamental paradigm for the development of complex Web applications, several security issues still need to be addressed. Among the various open issues concerning security, an important issue is represented by the development of suitable access control models, able to restrict access to Web services to authorized users. In this paper we present an innovative access control model for Web services. The model is characterized by a number of key features, including identity attributes and service negotiation capabilities. We also discuss an architecture implementing the model and we propose the use of a certificate scheme able to support the exchange and verification of subject attributes.

Original languageEnglish (US)
Title of host publicationProceedings - 2004 IEEE International Conference on Services Computing, SCC 2004
EditorsL.J. Zhang, M. Li, A.P. Sheth, K.G. Jeffery
Pages33-40
Number of pages8
DOIs
StatePublished - Oct 11 2004
EventProceedings - 2004 IEEE International Conference on Services Computing, SCC 2004 - Shanghai, China
Duration: Sep 15 2004Sep 18 2004

Publication series

NameProceedings - 2004 IEEE International Conference on Services Computing, SCC 2004

Other

OtherProceedings - 2004 IEEE International Conference on Services Computing, SCC 2004
Country/TerritoryChina
CityShanghai
Period9/15/049/18/04

All Science Journal Classification (ASJC) codes

  • Engineering(all)

Fingerprint

Dive into the research topics of 'A fine-grained access control model for Web services'. Together they form a unique fingerprint.

Cite this