A Web Service Architecture for Enforcing Access Control Policies

  • Authors:
  • Claudio Agostino Ardagna;Ernesto Damiani;Sabrina De Capitani di Vimercati;Pierangela Samarati

  • Affiliations:
  • Dipartimento di Tecnologie dell'Informazione, Università degli Studi di Milano, 26013 Crema, Italy;Dipartimento di Tecnologie dell'Informazione, Università degli Studi di Milano, 26013 Crema, Italy;Dipartimento di Tecnologie dell'Informazione, Università degli Studi di Milano, 26013 Crema, Italy;Dipartimento di Tecnologie dell'Informazione, Università degli Studi di Milano, 26013 Crema, Italy

  • Venue:
  • Electronic Notes in Theoretical Computer Science (ENTCS)
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Web services represent a challenge and an opportunity for organizations wishing to expose product and services offerings through the Internet. The Web service technology provides an environment in which service providers and consumers can discover each other and conduct business transactions through the exchange of XML-based documents. However, any organization using XML and Web Services must ensure that only the right users, sending the appropriate XML content, can access their Web Services. Access control policy specification for controlling access to Web services is then becoming an emergent research area due to the rapid development of Web services in modern economy. This paper is an effort to understand the basic concepts for securing Web services and the requirements for implementing secure Web services. We describe the design and implementation of a Web service architecture for enforcing access control policies, the overall rationale and some specific choices of our design are discussed.