Reasoning with semantics-aware access control policies for geospatial web services

  • Authors:
  • Ashraful Alam;Ganesh Subbiah;Bhavani Thuraisingam;Latifur Khan

  • Affiliations:
  • University of Texas at Dallas;University of Texas at Dallas;University of Texas at Dallas;University of Texas at Dallas

  • Venue:
  • Proceedings of the 3rd ACM workshop on Secure web services
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

A major obstacle on the way to the successful deployment and operation of Web services on a larger scale is a lack of sophisticated semantics model to represent and communicate the data. To solve the problem, semantics-aware Web services have been proposed. The other major huddle for Web services is the security architecture. Adding semantics to data adds an extra level of security vulnerability because there is scope for rouge agents to retrieve data that are not explicit in the original sources. Our goal is to propose and implement a security framework to thwart such security problems. Not only that, additionally, we demonstrate that proposed semantics can be utilized to cover security instances that would be impossible to achieve in semantics-unaware environment. We define a modular access control policy framework in the context of geospatial data integration platforms. Geospatial semantic Web services can employ the framework to enforce resource access and intelligently make decisions about policy rules. Our framework allows reasoning capabilities at both the resource enforcement point and service discovery point.