Implementing a modular access control service to support application-specific policies in CaesarJ

  • Authors:
  • Tine Verhanneman;Frank Piessens;Bart De Win;Eddy Truyen;Wouter Joosen

  • Affiliations:
  • DistriNet, K. U. Leuven, Leuven, Belgium;DistriNet, K. U. Leuven, Leuven, Belgium;DistriNet, K. U. Leuven, Leuven, Belgium;DistriNet, K. U. Leuven, Leuven, Belgium;DistriNet, K. U. Leuven, Leuven, Belgium

  • Venue:
  • AOMD '05 Proceedings of the 1st workshop on Aspect oriented middleware development
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Ideally, the enforcement of application-specific policies in an access control service should be untangled from the application logic. The access control services that are provided in state-of-the-art application servers typically fail to support such a separation. Aspect-Oriented Software Development techniques can be used to alleviate such shortcomings. This paper describes the design and implementation of a modular access control service that improves the separation between application logic and access control. The prototype has been implemented in CaesarJ.