A Model for Specification, Composition and Verification of Access Control Policies and Its Application to Web Services
Author(s):
Abstract:
Despite significant advances in the access control domain, requirements of new computational environments like web services still raise new challenges. Lack of appropriate method for specification of access control policies (ACPs), composition, verification and analysis of them have all made the access control in the composition of web services a complicated problem. In this paper, a new independent formal model called Constrained Policy Graph (CPG) for specification of ACPs and their composition as well as verification of conflict or incompatibility among the ACPs is represented. It is shown how CPG can be used in modeling and verification of web service composition ACPs. Also the application of CPG for modeling policies in BPEL processes -as the most common composition method for web services- is illustrated.
Keywords:
Language:
English
Published:
International Journal of Information Security, Volume:3 Issue: 2, Jul 2011
Pages:
103 to 120
https://www.magiran.com/p1205163
سامانه نویسندگان
مقالات دیگری از این نویسنده (گان)
-
CST-SDL: A Scenario Description Language for Collaborative Security Training in Cyber Ranges
Navid Shirmohammadi, *
International Journal of Information Security, Jan 2025 -
Intelligent Automation of Scenario Execution in Cyber Ranges Using Machine Learning Techniques
Farnoosh Karimi, *, Behrouz Shahgholi Ghahfarokhi
Journal Monadi for Cyberspace Security (AFTA),