2003 · 82 citations · 15 references
Hardware SecurityWs-securityEngineeringService SecurityLogical Access ControlInformation SecurityCryptographyAccess ControlXml SecuritySystems EngineeringSoftware EngineeringX-rbac SystemData ManagementPolicy SpecificationData SecurityFormal VerificationModel-driven Security
Policy specification for securing Web services is fast emerging as a key research area due to rapid proliferation of Web services in modern day enterprise applications. Whilst the use of XML technology to support these Web services has resulted in their tremendous growth, it has also introduced a new set of security challenges specific to these Web services. Though there has been recent research in areas of XML-based document security, these challenges have not been addressed within the XML framework. In this paper, we present X-RBAC, an XML-based RBAC policy specification framework for enforcing access control in dynamic XML-based Web services. An X-RBAC system has been implemented as a Java application, and is based on a specification language that addresses specific security requirements of these Web services. We discuss the salient features of the specification language, and present the software architecture of our X-RBAC system.
15
Role-based access control models
Ravi Sandhu, Edward J. Coyne, H.L. Feinstein et al. · Computer · 1996 · 5.8K citations
The NIST model for role-based access control
Ravi Sandhu, David Ferraiolo, Richard Kühn · 2000 · 867 citations · Full text
Hardware Security, Flat Rbac, Authentication Authorization +14