支持授权和创建权限的web服务访问控制模型

Mitsuhiro Mabuchi, Yasushi Shinjo, Akira Sato, Kazuhiko Kato
{"title":"支持授权和创建权限的web服务访问控制模型","authors":"Mitsuhiro Mabuchi, Yasushi Shinjo, Akira Sato, Kazuhiko Kato","doi":"10.1109/ICN.2008.72","DOIUrl":null,"url":null,"abstract":"We present a new access control model for XML Web-Services that provides users with two kinds of authorities: the authority to delegate their authorities to other users and the authority to create new authorities based on their own authorities. We developed this model by introducing capability- based access control to Web services. A capability consists of an object identifier and the list of permitted operations for that object. We map an authority of a Web-Services object to a capability of the object and express the capability as a description in Web Services Description Language (WSDL). Delegation of an authority corresponds to distribution of a capability, which is done by passing a WSDL description. Creation of a new authority corresponds to generating a restricted capability based on an original capability, which is done by stacking an object on an original object. Stacking objects also makes it possible to add new functions to existing Web-Services objects without modifying the existing objects. We demonstrate the effectiveness of the proposed model using a schedule management application, which enables a project leader to delegate his or her tasks to subordinates by comparing it with Google Calendar. We also show that the execution times of stackable objects are acceptable by comparing them with typical Internet delay.","PeriodicalId":250085,"journal":{"name":"Seventh International Conference on Networking (icn 2008)","volume":"7 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-04-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":"{\"title\":\"An Access Control Model for Web-Services That Supports Delegation and Creation of Authority\",\"authors\":\"Mitsuhiro Mabuchi, Yasushi Shinjo, Akira Sato, Kazuhiko Kato\",\"doi\":\"10.1109/ICN.2008.72\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"We present a new access control model for XML Web-Services that provides users with two kinds of authorities: the authority to delegate their authorities to other users and the authority to create new authorities based on their own authorities. We developed this model by introducing capability- based access control to Web services. A capability consists of an object identifier and the list of permitted operations for that object. We map an authority of a Web-Services object to a capability of the object and express the capability as a description in Web Services Description Language (WSDL). Delegation of an authority corresponds to distribution of a capability, which is done by passing a WSDL description. Creation of a new authority corresponds to generating a restricted capability based on an original capability, which is done by stacking an object on an original object. Stacking objects also makes it possible to add new functions to existing Web-Services objects without modifying the existing objects. We demonstrate the effectiveness of the proposed model using a schedule management application, which enables a project leader to delegate his or her tasks to subordinates by comparing it with Google Calendar. We also show that the execution times of stackable objects are acceptable by comparing them with typical Internet delay.\",\"PeriodicalId\":250085,\"journal\":{\"name\":\"Seventh International Conference on Networking (icn 2008)\",\"volume\":\"7 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2008-04-13\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"10\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Seventh International Conference on Networking (icn 2008)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICN.2008.72\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Seventh International Conference on Networking (icn 2008)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICN.2008.72","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10

摘要

我们为XML Web-Services提出了一种新的访问控制模型,它为用户提供了两种类型的权限:将自己的权限委托给其他用户的权限和基于自己的权限创建新权限的权限。我们通过向Web服务引入基于功能的访问控制来开发这个模型。功能由对象标识符和该对象允许的操作列表组成。我们将Web-Services对象的权限映射到该对象的功能,并将该功能表示为Web服务描述语言(WSDL)中的描述。授权对应于功能的分布,这是通过传递WSDL描述来完成的。新权限的创建对应于基于原始功能生成受限制的功能,这是通过在原始对象上堆叠对象来完成的。堆叠对象还可以在不修改现有对象的情况下向现有Web-Services对象添加新功能。我们使用日程管理应用程序演示了所建议模型的有效性,该应用程序使项目负责人能够通过将其与Google Calendar进行比较,将其任务委派给下属。通过将可堆叠对象的执行时间与典型的Internet延迟进行比较,我们也证明了可堆叠对象的执行时间是可以接受的。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
An Access Control Model for Web-Services That Supports Delegation and Creation of Authority
We present a new access control model for XML Web-Services that provides users with two kinds of authorities: the authority to delegate their authorities to other users and the authority to create new authorities based on their own authorities. We developed this model by introducing capability- based access control to Web services. A capability consists of an object identifier and the list of permitted operations for that object. We map an authority of a Web-Services object to a capability of the object and express the capability as a description in Web Services Description Language (WSDL). Delegation of an authority corresponds to distribution of a capability, which is done by passing a WSDL description. Creation of a new authority corresponds to generating a restricted capability based on an original capability, which is done by stacking an object on an original object. Stacking objects also makes it possible to add new functions to existing Web-Services objects without modifying the existing objects. We demonstrate the effectiveness of the proposed model using a schedule management application, which enables a project leader to delegate his or her tasks to subordinates by comparing it with Google Calendar. We also show that the execution times of stackable objects are acceptable by comparing them with typical Internet delay.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
An Application Layer Multicast for Collaborative Scenarios: The OMCAST Protocol Reduce Time Synchronization Cost for High Latency and Resource-Constrained Sensor Networks Restoration Mechanism for the N2R Topological Routing Algorithm A Hierarchical Game for Uplink CDMA Transmissions with Random Active Users Multicast Voice Transmission over Vehicular Ad Hoc Networks: Issues and Challenges
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1