作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (7): 137-138,. doi: 10.3969/j.issn.1000-3428.2008.07.048

• 安全技术 • 上一篇    下一篇

一种基于访问控制的安全Web服务发现机制

韩 隽1,2,淮晓永1,赵 琛1   

  1. 韩 隽1,2,淮晓永1,赵 琛1
    (1. 中国科学院软件研究所互联网技术实验室,北京 100080;2. 中国科学院研究生院,北京 100039)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-04-05 发布日期:2008-04-05

Secure Web Services Discovery Method Based on Access Control

HAN Jun1,2, HUAI Xiao-yong1, ZHAO Chen1   

  1. (1. Lab for Internet Technology, Institute of Software, Chinese Academy of Sciences, Beijing 100080; 2. Graduate University of Chinese Academy of Sciences, Beijing 100039)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-04-05 Published:2008-04-05

摘要: 当前的Web服务发现机制大多依赖集中式的统一描述、发现和集成注册中心,但组织机构出于安全和地域的考虑,倾向于构建私有的分布式注册中心,只有注册且可信的请求者才能浏览到他们有权限访问的服务信息。该文给出Web服务发现阶段基于角色的访问控制模型RBAC4WSD,发现代理依照服务提供者指定的安全策略对请求者实施访问控制,并以跨国公司内部的文档服务为例介绍原型系统的实现。

关键词: Web服务, 发现代理, 统一描述、发现和集成, 基于角色的访问控制, 隐私保护

Abstract: Most current Web services discovery methods rely on centralized UDDI registries. Due to the security and area, organizations usually build distributed private registries and enforce access control mechanisms. The registered and trusted people can browse the information of services they have permissions to access. A RBAC model for Web services discovery phase named RBAC4WSD is proposed. Discovery agencies are designed to perform access control on service requestors upon security policies specified by service providers. In terms of a scenario of distributed document service within a multinational company, a prototype system is described.

Key words: Web services, discovery agency, lUDDI, RBAC, privacy protection

中图分类号: