| Policy expression and checking in XACML, WS-Policies, and the jABC |
| Full text |
Pdf
(609 KB)
|
| Source
|
International Symposium on Software Testing and Analysis
archive
Proceedings of the 2008 workshop on Testing, analysis, and verification of web services and applications
table of contents
Seattle, Washington
Pages 20-26
Year of Publication: 2008
ISBN:978-1-60558-053-1
|
|
Authors
|
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 13, Downloads (12 Months): 122, Citation Count: 0
|
|
|
ABSTRACT
Web-based access to sensitive and confidential data is realized today via different approaches, using a variety of methods to specify and combine access control policies. In an optic of change management and evolution, a structured and flexible model is needed to handle dynamicity, particularly when handling rights in systems with many users which hold different roles. Furthermore the validation of security constraints is an important key to warrant the reliability of control mechanisms. This paper compares the temporal logic-based approach for modeling access control used by the jABC framework with two popular XML-based description languages (XACML and WS-Policy), which are quasi-standards for policy expression in Web applications. Its usage is illustrated here on the example of the web-based Online Conference Service (OCS). The respective functionalities are described and examined in consideration of their ability to validate and enforce the needed policies.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
T. Moses (Ed.): eXtensible Access Control Markup Language (XACML) Version 2.0, Feb. 2005 http://docs.oasis-open.org/xacml/2.0/access_control-xacml-2.0-core-spec-os. pdf,
|
| |
2
|
P. Griffin: Introduction to XACML, February 2004 http://dev2dev.bea.com/pub/a/2004/02/xacml.html
|
| |
3
|
B. Siddharth et al.: Web Services Policy 1.2 - Framework (WS-Policy), April 2006, http://www.w3.org/Submission/2006/SUBM-WS-Policy-20060425/
|
| |
4
|
E. A. Emerson, C. S. Jutla, A. P. Sistla. On model-checking for fragments of μ-calculus. 1993.
|
| |
5
|
G. Hughes, T. Bultan: Automated Verification of XACML Policies Using a SAT Solver. WQVV 2007, Worksh. on Web Quality, Verification and Validation, at 7th ICWE, Como (I), July 2007, Worksh. Proc. pp. 378--392.
|
| |
6
|
|
| |
7
|
M. Karusseit, T. Margaria: Feature-based Modelling of a Complex, Online-Reconfigurable Decision Support Service Proc. WWV '05, 1st Int. Worksh. on Automated Specification and Verification of Web Sites, Valencia (E), March 2005, ENTCS N. 1132.
|
| |
8
|
|
| |
9
|
jABC: JavaABC Framework http://www.jABC.de
|
| |
10
|
B. Steffen, T. Margaria, R. Nagel, S. Jörges, C. Kubczak: Model-Driven Development with the jABC, Proc. HVC '06, IBM Haifa Verification Conf., Haifa (IL), LNCS 4383, Springer Verlag, 2006.
|
| |
11
|
|
| |
12
|
|
 |
13
|
|
| |
14
|
OASIS http://www.oasis-open.org/home/index.php
|
| |
15
|
Della-Libera et al.: Web Services Security Policy Language (WS-SecurityPolicy) Version 1.1, July 2005 http://specs.xmlsoap.org/ws/2005/07/securitypolicy/ws-securitypolicy.pdf
|
| |
16
|
D. Box et al.: Web Services Policy Assertions Language (WS-PolicyAssertions) Version 1.1, May 2003 http://xml.coverpages.org/ws-policyassertionsV11.pdf
|
| |
17
|
K. Ballinger et al.: Web Services Metadata Exchange (WS-MetadataExchange) Version 1.1 August 2006 http://specs.xmlsoap.org/ws/2004/09/mex/WS-MetadataExchange.pdf,
|
| |
18
|
M. Bakera, T. Margaria, C. Renner, B. Steffen: Game-based Model Checking for Reliable Autonomy, SMC-IT '06, 2nd IEEE Int. Conf. on Space Mission Challenges for Information Technology, Workshop on Autonomous and Autonomic Systems, July 2006.
|
|