计算机科学 ›› 2010, Vol. 37 ›› Issue (7): 125-129.

• 软件工程 • 上一篇    下一篇

面向Web服务资源的两层访问控制方法

霍远国,马殿富,刘建,李竹青   

  1. (北京航空航天大学计算机学院 北京100191)
  • 出版日期:2018-12-01 发布日期:2018-12-01
  • 基金资助:
    本文受863国家重点基金项目“高可信软件生产工具及集成环境”(2007AA010301)资助。

Attribute-based Two Level Access Control for Web Service Resources

HUO Yuan-guo,MA Dian-fu,LIU Jian,LI Zhu-qing   

  • Online:2018-12-01 Published:2018-12-01

摘要: Web服务资源具有静态的Web服务接口和动态的有状态资源两个组件。针对这两个组件的不同特征为它提出一种基于属性的两层访问控制方法(Two Level Attribute-Based Access Control, 2L-ABAC)。2L-ABAC扩展基于属性的访问控制模型(Attribute-Based Access Control, ABAC),对这两个组件分别进行访问控制。ABAC系统的访问决定依赖于用户提供的主体属性,所以2L-ABAC采用策略发布机制告知用户所需的属性,并根据各层特征分别采用WSDL附件和元数据交换两种发布方式。除了分层设计带来的灵活性,2L-ABAC还继承了ABAC模型的特性,能够对来自其他安全域的用户进行访问控制。另外,它基于相关国际规范实现,如XACML和SAML,故具有通用性。

关键词: Web服务资源,基于属性的访问控制,WSDL, XACML, SAML

Abstract: Web Services Resource (WS-Resource) consists of static Web service interface and dynamic stateful resource. According to the different characteristics of the two components, we proposed an Attribute-Based Two Level Access Control (2L-ABAC) on for WS-Resources. Attribute retrieval is essential for ABAC systems because they are based on their decisions on attributes of users, so 2L-ABAC employs access control policies publishing mechanism to inform users of the needed attributes. Access control policies of Web Services are static and those of resources arc dynamic,correspondently two publishing methods, WSDL attachment and metadata exchanging, are adopted for each level respectively. 2L-ABAC inherits from the ABAC model the capability of authorizing unknown users from other security domains, besides its flexibility due to the hierarchy design model. Moreover, this architecture can be implemented by extending the standard specifications such as XACML and SAML, so it has broad applicability for WS-Resource based systems.

Key words: WS-Resource, ABAC, WSDL, XACML SAML

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!