Business Processes for Web Services are the new paradigm for the lightweight integration of business from different enterprises. Whereas the security and access control policies for basic web services and distributed systems are well studied and almost standardized, there is not yet a comprehensive proposal for an access control architecture for business processes. The major issue is that a business process describe complex services that cross organizational boundaries and are provided by entities that see each other as just partners and nothing else. This calls for a number of differences with traditional aspects of access control architectures such as Credential vs classical user-based access control, Cnteractive and partner-based vs one-server-gathers-all requests of credentials from clients, Controlled disclosure of information vs all-or-nothing access control decisions, Abducing missing credentials for fulfilling requests vs deducing entailment of valid requests from credentials i...

An Access Control Framework for Business Processes for Web Services

Koshutanski, Hristo;Massacci, Fabio
2003-01-01

Abstract

Business Processes for Web Services are the new paradigm for the lightweight integration of business from different enterprises. Whereas the security and access control policies for basic web services and distributed systems are well studied and almost standardized, there is not yet a comprehensive proposal for an access control architecture for business processes. The major issue is that a business process describe complex services that cross organizational boundaries and are provided by entities that see each other as just partners and nothing else. This calls for a number of differences with traditional aspects of access control architectures such as Credential vs classical user-based access control, Cnteractive and partner-based vs one-server-gathers-all requests of credentials from clients, Controlled disclosure of information vs all-or-nothing access control decisions, Abducing missing credentials for fulfilling requests vs deducing entailment of valid requests from credentials i...
2003
XML security (XMLSEC-2003)
USA
ACM Press
9781581137774
Koshutanski, Hristo; Massacci, Fabio
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11572/53995
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 73
  • ???jsp.display-item.citation.isi??? ND
  • OpenAlex ND
social impact