KIT | KIT-Bibliothek | Impressum | Datenschutz

Model-Driven Development of Access Control Policies for Web Services

Emig, Christian; Kreuzer, Sebastian; Abeck, Sebastian

Abstract:

Web service-oriented architecture (WSOA) is a promising paradigm for future software development. Necessary identity management (IdM) architectures for WSOA are just being prepared to enable fine-grained access control. With the loose coupling of Web services with cross-cutting identity services the question arises how to develop access control policies for Web services. In this paper we present a model-driven approach defining access control policies which are independent from the IdM architecture to which they are later applied. Therefore we develop a platform-independent access control model for WSOA and derive a platform-specific model from a given IdM product. We show how to map both models to a concrete language. Access control policies are then defined using our platform-independent language and transformed to platform-specific policies using explicitly defined transformation rules. We present a case study that applies our approach.


Volltext §
DOI: 10.5445/IR/1000008041
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Telematik (TM)
Publikationstyp Forschungsbericht/Preprint
Publikationsjahr 2008
Sprache Englisch
Identifikator urn:nbn:de:swb:90-80418
KITopen-ID: 1000008041
Serie C&M Research Report
Externe Relationen Siehe auch
KIT – Die Forschungsuniversität in der Helmholtz-Gemeinschaft
KITopen Landing Page