Close category search window
 

A parameterized RBAC access control model for WS-BPEL orchestrated composite web services

Sign In

Cookies must be enabled to login.After enabling cookies , please use refresh or reload or ctrl+f5 on the browser for the login options.

Formats Non-Member Member
$31 $13
Learn how you can qualify for the best price for this item!
Become an IEEE Member or Subscribe to
IEEE Xplore for exclusive pricing!
close button

puzzle piece

IEEE membership options for an individual and IEEE Xplore subscriptions for an organization offer the most affordable access to essential journal articles, conference papers, standards, eBooks, and eLearning courses.

Learn more about:

IEEE membership

IEEE Xplore subscriptions

2 Author(s)
Nassr, N. ; Dept. Comput. Sci. & Eng., Katholieke Univ. Leuven, Leuven, Belgium ; Steegmans, E.

In complex environments multiple web services are needed to interoperate together. Web Services Business Process Execution Language (WS-BPEL) has become the de facto standard for orchestrating composite web services. Unfortunately, WS-BPEL bypasses some business mandatory security requirements such as authentication and authorization. However, there have been some initiatives to address the authorization-bypass security vulnerability in WS-BPEL through integration with access control models such as RBAC. However, the RBAC models used lack expressiveness in role definitions and in roles to permissions mappings. More so, the architectures proposed use sequential authorization that is inefficient for long running business processes. In this paper, we extend the parameterized RBAC model and integrate it with WS-BPEL. The new extended parameterized RBAC model for WS-BPEL provides restriction of access up to the level of the variables of the business process. We also provide a new algorithm for authorization enforcement that addresses limitations of exiting WS-BPEL authorization architectures.

Published in:
Internet Technology and Secured Transactions (ICITST), 2011 International Conference for

Date of Conference: 11-14 Dec. 2011

Need Help?


IEEE Advancing Technology for Humanity About IEEE Xplore | Contact | Help | Terms of Use | Nondiscrimination Policy | Site Map | Privacy & Opting Out of Cookies

A not-for-profit organization, IEEE is the world's largest professional association for the advancement of technology.
© Copyright 2013 IEEE - All rights reserved. Use of this web site signifies your agreement to the terms and conditions.