A Trust-based Context-Aware Access Control Model for Web-Services

  • Authors:
  • Rafae Bhatti;Elisa Bertino;Arif Ghafoor

  • Affiliations:
  • Purdue University, West Lafayette, IN;Purdue University, West Lafayette, IN;Purdue University, West Lafayette, IN

  • Venue:
  • ICWS '04 Proceedings of the IEEE International Conference on Web Services
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

A key challenge in Web services security is the designof effective access control schemes that can adequatelymeet the unique security challenges posed by the Webservices paradigm. Despite the recent advances in Webbased access control approaches applicable to Webservices, there remain issues that impede thedevelopment of effective access control models forWeb services environment. Amongst them are the lackof context-aware models for access control, andreliance on identity or capability-based access controlschemes. In this paper, we motivate the design of anaccess control scheme that addresses these issues, andpropose an extended, trust-enhanced version of ourXML-based Role Based Access Control (X-RBAC)framework that incorporates context-based accesscontrol. We outline the configuration mechanismneeded to apply our model to the Web servicesenvironment, and also describe the implementationarchitecture for the system.