Font Size: a A A

Research And Application Of Access Control Based On Attribute And Negotiation In Service-oriented Environment

Posted on:2011-03-11Degree:MasterType:Thesis
Country:ChinaCandidate:J CengFull Text:PDF
GTID:2178360308958199Subject:Computer software and theory
Abstract/Summary:
The Service-Oriented Architecture (SOA) becomes increasingly popular nowadays, for the capability of enterprise-level resources integration, as well as a general solution it provides for the problems that caused by the "information islands". One drawback existed within a SOA-based system is unable to identify the user identity, which is due to the limitation on the role-and-permission-based access authorization within a traditional access control mechanism. The problem tends worsen when it comes to a dynamic service-oriented environment whose business requirements changing rapidly, where this inherent defect could hinder the scalability and update of one such system which could have been distributed, heterogeneous and dynamic.The work in this paper is a sub-project of the"Key Technology Research and Application of the Survey and Design Enterprise Informationization"project, a Scientific Research Project funded by the National Science and Technology Pillar Program during the Eleventh Five-Year Plan Period. An attribute-and-negotiation-based access control model is proposed in terms of the study upon the SOA environment and the traditional access control models. With the support of the Security Assertion Markup Language (SAML), the Single Sign-on is implemented to provide attribute certification. The attribute-and-negotiation-based access authorization is enabled by adopting the Extensible Access Control Markup Language (XACML). Then the proposed access control prototype system is deployed within the Survey and Design Institute-level SOA framework.This paper has accomplished the following tasks:①Analyzed and compared the pros and cons of service-oriented environment, with those traditional access control models, and concluded drawbacks of the latter with applicable scenarios.②Studied the authorization mechanism of Attribute-Based Access Control (ABAC) models, and improved it according to the characteristics of service-oriented environment. Meanwhile, the advantages of the improved model were presented.③Investigated the negotiating mechanism in ABAC model, and proposed an attribute-and-negotiation-based access control framework based on the improved ABAC model. Studied the user sensitive attributes protection in negotiating mechanism, and then compared the improved model with its original ABAC counterpart. ④Devised and implemented an attribute-and-negotiation-based access control prototype system in service-oriented environment. Enabled the attribute certification with Single Sign-on using SAML. Provided the sensitive attribute protection upon a negotiating mechanism, and the attribute-and-negotiation-based access authorization.⑤Deployed the proposed attribute-and-negotiation-based access control model within the Survey and Design Institute-level SOA framework. Tested and analyzed the access authorization security of the prototype system, and suggested suitable scenarios of this proposed attribute-and-negotiation-based access control.
Keywords/Search Tags:Service Oriented environment, Access Control, Negotiating Mechanism, Sensitive Attribute Protection, Policy
Related items