A Web service architecture for enforcing access control policies

Claudio Agostino Ardagna, Ernesto Damiani, Sabrina De Capitani Di Vimercati, Pierangela Samarati

Research output: Contribution to journalArticlepeer-review

36 Scopus citations

Abstract

Web services represent a challenge and an opportunity for organizations wishing to expose product and services offerings through the Internet. The Web service technology provides an environment in which service providers and consumers can discover each other and conduct business transactions through the exchange of XML-based documents. However, any organization using XML and Web Services must ensure that only the right users, sending the appropriate XML content, can access their Web Services. Access control policy specification for controlling access to Web services is then becoming an emergent research area due to the rapid development of Web services in modern economy. This paper is an effort to understand the basic concepts for securing Web services and the requirements for implementing secure Web services. We describe the design and implementation of a Web service architecture for enforcing access control policies, the overall rationale and some specific choices of our design are discussed.

Original languageBritish English
Pages (from-to)47-62
Number of pages16
JournalElectronic Notes in Theoretical Computer Science
Volume142
Issue numberSPEC. ISS.
DOIs
StatePublished - 3 Jan 2006

Keywords

  • Distributed systems
  • Interoperability
  • Security
  • Web Services
  • XML

Fingerprint

Dive into the research topics of 'A Web service architecture for enforcing access control policies'. Together they form a unique fingerprint.

Cite this