KIT | KIT-Bibliothek | Impressum | Datenschutz

Model-Driven Development of Access Control Policies for Web Services

Emig, Christian; Kreuzer, Sebastian; Abeck, Sebastian; Biermann, Jürgen; Klarl, Heiko

Abstract:

Web service-oriented architecture (WSOA) is a promising paradigm for future software development. Necessary identity management (IdM) architectures for WSOA are just being prepared to enable fine-grained access control. With the loose coupling of Web services with crosscutting identity services the question arises how to develop access control policies for Web services. In this paper we present a model-driven approach defining access control policies which are independent from the IdM architecture to which they are later applied. Therefore we develop a platform-independent access control model for WSOA and derive a platform-specific model from a given IdM product. We show how to map both models to a concrete language. Access control policies are then defined using our platform-independent language and transformed to platform-specific policies using explicitly defined transformation rules. We present a case study that applies our approach.


Volltext §
DOI: 10.5445/IR/1000009884
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Telematik (TM)
Publikationstyp Proceedingsbeitrag
Publikationsjahr 2008
Sprache Englisch
Identifikator ISBN: 978-0-88986-775-8
urn:nbn:de:swb:90-98846
KITopen-ID: 1000009884
Erschienen in Proceedings of the 9th IASTED International Conference on Software Engineering and Applications (SEA 2008), Nov. 16-18, 2008, Orlando, Florida, USA
Verlag ACTA Press
Seiten 165-171
KIT – Die Forschungsuniversität in der Helmholtz-Gemeinschaft
KITopen Landing Page