Designing secure e-commerce with role-based access control

  • Authors:
  • Cungang Yang

  • Affiliations:
  • Department of Electrical and Computer Engineering, Ryerson University, Toronto, Ontario M5B 2K3, Canada

  • Venue:
  • International Journal of Web Engineering and Technology
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, an Object-Oriented Role-Based Access Control (ORBAC) model for e-commerce is introduced. Based on the model, an efficient method for managing ORBAC security policies using eXtensible Markup Language (XML) and a role assignment algorithm are presented. The proposed method using digital credentials and an XML-based security policy greatly simplifies security policy administration for e-commerce. Also, an implementation of e-commerce applications is described. Unlike most existing approaches, with our approach the authorisation is independently defined and is separated from implementation mechanisms.