作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (01): 148-150. doi: 10.3969/j.issn.1000-3428.2007.01.051

• 安全技术 • 上一篇    下一篇

基于进程的Web服务访问控制模型

李国辉1,2,罗铁坚1,2,宋进亮1,2   

  1. (1. 中国科学院研究生院,北京 100049;2. 信息安全国家重点实验室,北京 100049)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-01-05 发布日期:2007-01-05

Access Control Model for Web Services Based on Process

LI Guohui1,2, LUO Tiejian1,2, SONG Jinliang1,2   

  1. (1. Graduate School of Chinese Academy of Sciences, Beijing 100049; 2. State Key Laboratory of Information Security, Beijing 100049)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-01-05 Published:2007-01-05

摘要: 在对传统RBAC研究的基础上,针对Web Services低耦合、动态变化的特点提出了针对Web Services的访问控制模型——PBACWS。PBACWS中提出了元服务、元权限的概念对Web Services进行了描述。PBACWS突破了RBAC中对用户赋予角色的做法,利用服务权限令牌进行授权的概念,通过将动态生成的服务权限令牌赋予任务进程,实现了对Web Services进行细粒度的安全控制。

关键词: Web Services, 访问控制, Web Services的访问控制模型, 服务权限令牌

Abstract: A new kind of access control model——PBACWS(process based access model for Web Services) is invented concentrating on the low coupling and dynamic change characters of Web Services. Under the PBACWS model, concepts of meta service and meta permission are put forward to give better description of Web Services and it changes the tradition way of assigning user with role to use service permission token as the authorization entity. In this model, more effective access control for Web Services is made through assigning the task process with the dynamic service permission token.

Key words: Web Services, Access control, Process based access model for Web Services (PBACWS), Service permission token