A Semantic-Aware Attribute-Based Access Control Model for Web Services

Web service is a new service-oriented computing paradigm which poses the unique security challenges due to its inherent heterogeneity, multi-domain characteristic and highly dynamic nature. A key challenge in Web services security is the design of effective access control schemes. Attribute-based access control (ABAC) is more appropriate than some other access control mechanisms, but it do not fully exploit the semantic power and reasoning capabilities of emerging web applications. So a semantic-aware attribute-based access control model (SABAC) is presented to address these issues by combining the ABAC with the Semantic Web technologies in this paper. SABAC grants access to services based on attributes of the related entities, and uses Shibboleth service to address the disclosure issue of the sensitive attributes. In addition, SABAC uses the Web Ontology Language (OWL) standard to represent the ontology of the resources and users and uses eXtensible Access Control Markup Language (XACML) as the policy language. It can provide administratively scalable alternative to identity-based authorization methods and provide semantic interoperability for the access control to Web services. Moreover, SABAC also separates ontology management from access management.

[1]  Tim Moses,et al.  EXtensible Access Control Markup Language (XACML) version 1 , 2003 .

[2]  G Stix,et al.  The mice that warred. , 2001, Scientific American.

[3]  Ernesto Damiani,et al.  Extending Context Descriptions in Semantics-Aware Access Control , 2006, ICISS.

[4]  Marijke Coetzee A Logic-Based Access Control Approach For Web Services , 2004, ISSA.

[5]  Yi Pan,et al.  Grid and Cooperative Computing - GCC 2004 Workshops , 2004, Lecture Notes in Computer Science.

[6]  Ravi Sandhu Access Control: The Neglected Frontier , 1996, ACISP.

[7]  Jin Tong,et al.  Attributed based access control (ABAC) for Web services , 2005, IEEE International Conference on Web Services (ICWS'05).

[8]  Nora Kamprath,et al.  Supporting attribute-based access control with ontologies , 2006, First International Conference on Availability, Reliability and Security (ARES'06).

[9]  Leon Gommans,et al.  Extending Role Based Access Control Model for Distributed Multidomain Applications , 2007, SEC.

[10]  Fan Hong,et al.  An Attribute-Based Access Control Model for Web Services , 2006, PDCAT.

[11]  Jan H. P. Eloff,et al.  A Trust and Context Aware Access Control Model for Web Services Conversations , 2007, TrustBus.

[12]  Elisa Bertino,et al.  A Trust-Based Context-Aware Access Control Model for Web-Services , 2004, Proceedings. IEEE International Conference on Web Services, 2004..

[13]  H. Lan,et al.  SWRL : A semantic Web rule language combining OWL and ruleML , 2004 .

[14]  James A. Hendler,et al.  The Semantic Web" in Scientific American , 2001 .

[15]  Deborah L. McGuinness,et al.  OWL Web ontology language overview , 2004 .

[16]  Miao Liu,et al.  An attribute and role based access control model for Web services , 2005, 2005 International Conference on Machine Learning and Cybernetics.

[17]  E. Damiani,et al.  New paradigms for access control in open environments , 2005, Proceedings of the Fifth IEEE International Symposium on Signal Processing and Information Technology, 2005..

[18]  Xie Jun,et al.  Context-Aware Role-Based Access Control Model for Web Services , 2004 .

[19]  Jim Duggan,et al.  Using semantic rules to determine access control for web services , 2006, WWW '06.

[20]  Ravi S. Sandhu,et al.  A model for attribute-based user-role assignment , 2002, 18th Annual Computer Security Applications Conference, 2002. Proceedings..

[21]  Ramaswamy Chandramouli,et al.  The Queen's Guard: A Secure Enforcement of Fine-grained Access Control In Distributed Data Analytics Platforms , 2001, ACM Trans. Inf. Syst. Secur..

[22]  Information Security and Privacy , 1996, Lecture Notes in Computer Science.

[23]  Vijayalakshmi Atluri,et al.  Using semantics for automatic enforcement of access control policies among dynamic coalitions , 2007, SACMAT '07.

[24]  Hong Fan,et al.  A context-aware role-based access control model for Web services , 2005, IEEE International Conference on e-Business Engineering (ICEBE'05).

[25]  V. Welch,et al.  Attributes , Anonymity , and Access : Shibboleth and Globus Integration to Facilitate Grid Collaboration , 2005 .

[26]  Huajun Chen,et al.  The Semantic Web , 2011, Lecture Notes in Computer Science.

[27]  Eduardo B. Fernández,et al.  A Pattern System for Access Control , 2004, DBSec.

[28]  Ernesto Damiani,et al.  Fine grained access control for SOAP E-services , 2001, WWW '01.

[29]  Mirina Grosz,et al.  World Wide Web Consortium , 2010 .