Guaranteebased access control model for Web services
YAN Xuexiong1,WANG Qingxian1,MA Hengtai2
(1.Institute of Information Engineering, PLA Information Engineering University, Zhengzhou450002,China; 2.Institute of Software, Chinese Academy of Sciences, Beijing 100080,China)
Abstract:This article presented a new access control model for Web services that bases on guarantee(s). It was a formal model, and the key point of the model was that the subject and the provider of the Web services could contact with one another through a guarantor(s), which could made a guarantee for the subject. Multi guarantees made up a guarantee chain. By using the guarantee chain, the subject could get the authorization of the Web services to some degrees of trust. This article also described an access decision algorithm and an application example of this model.......