科技报告详细信息
Solving the Transitive Access Problem for the Services Oriented Architecture
Karp, Alan H. ; Li, Jun
HP Development Company
关键词: SOA;    web services;    access control;    RBAC;    PBAC;    ABAC;    ZBAC;   
RP-ID  :  HPL-2008-204R1
学科分类:计算机科学(综合)
美国|英语
来源: HP Labs
PDF
【 摘 要 】

A key goal of the Services Oriented Architecture is the composition of independently written and managed services. However, managing access to these services has proven to be a problem. A particularly difficult case involves a service that invokes another service to satisfy an initial request. In a number of cases, implementations are able to achieve either the desired functionality or the required security, but not both at the same time. We say that this service composition suffers from the transitive access problem. We show that the problem arises from a poor choice of access control mechanism, one that uses authentication to make access decisions, and that the problem does not occur if we use delegatable authorizations.

【 预 览 】
附件列表
Files Size Format View
RO201804100002121LZ 496KB PDF download
  文献评价指标  
  下载次数:32次 浏览次数:62次