Business Processes for Web Services (BPEL4WS) are the new paradigms for lightweight enterprise integration. They cross organizational boundaries and are provided by entities that see each other just as business partners. Web services require shift in the access control mechanism: from identity-based access control to trust management and negotiation, but thi s is not enough for cross organizational busin ess processes. For many businesses no partner may guess apriori what kind of credentials will be sent by clients and clients may not know apriori which credentials are required for completing a business process. We pro pose a logical framework for reasoning about access control for BPEL4WS and a BPEL4WS based implementation usin g Collaxa server. Our model is based on int eraction a nd exchange of requ ests for supplying or declining missing crede nt ials. We identify the formal reasoning services (deduction, abduct ion, consiste ncy checking) that characterise problem and discuss thei...

Interactive Access Control for Web Services

Koshutanski, Hristo;Massacci, Fabio
2004-01-01

Abstract

Business Processes for Web Services (BPEL4WS) are the new paradigms for lightweight enterprise integration. They cross organizational boundaries and are provided by entities that see each other just as business partners. Web services require shift in the access control mechanism: from identity-based access control to trust management and negotiation, but thi s is not enough for cross organizational busin ess processes. For many businesses no partner may guess apriori what kind of credentials will be sent by clients and clients may not know apriori which credentials are required for completing a business process. We pro pose a logical framework for reasoning about access control for BPEL4WS and a BPEL4WS based implementation usin g Collaxa server. Our model is based on int eraction a nd exchange of requ ests for supplying or declining missing crede nt ials. We identify the formal reasoning services (deduction, abduct ion, consiste ncy checking) that characterise problem and discuss thei...
2004
Security and protection in information processing systems: IFIP 18th world computer congress: TC11 19th International Information Security Conference
Boston
Kluwer Academic Publishers
9781475780161
Koshutanski, Hristo; Massacci, Fabio
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11572/77739
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 26
  • ???jsp.display-item.citation.isi??? 12
  • OpenAlex ND
social impact