Methodological model for authorization management in microservices-based applications
Daniel Oswaldo Ramírez Guevara
Additional contact information
Daniel Oswaldo Ramírez Guevara: Instituto Sapiens de Investigación Científica Multidisciplinar. Milagro, Ecuador.
CognitivaTech: IngenierÃa de Software Inteligente y Sistemas Adaptativos, 2024, vol. 1, issue 1, 3
Abstract:
The growing adoption of microservices-based architectures has transformed software development by enabling distributed, scalable, and loosely coupled systems; however, this evolution has also increased the complexity of access control management, particularly in terms of authorization. In this context, this research proposes a methodological approach to systematically integrate authorization policies into the software development lifecycle of microservice-based applications. The study follows a descriptive–analytical design structured into four stages: authorization requirements analysis, policy formalization, implementation within a distributed architecture, and validation through a case study. The results show that the use of the Attribute-Based Access Control (ABAC) model allows the definition of more precise and flexible rules compared to traditional role-based approaches, reducing redundancy and improving system adaptability. Additionally, separating authorization logic from business logic proved essential for enhancing maintainability and scalability, enabling policy modifications without affecting the services. The validation phase demonstrated that the early integration of authorization helps maintain consistency across requirements, design, and implementation, avoiding inconsistencies and rework. However, the findings also indicate that properly defining attributes requires a rigorous initial analysis. In conclusion, the proposed approach improves authorization management in microservices by providing a structured, coherent, and adaptable framework, contributing to the development of more secure and efficient systems.
Keywords: microservices; access control; ABAC; software security. (search for similar items in EconPapers)
Date: 2024
References: Add references at CitEc
Citations:
Downloads: (external link)
https://cognitivatech.org/index.php/cognitivatech/article/view/3 Abstract page (text/html)
https://cognitivatech.org/index.php/cognitivatech/article/download/3/28 Full text (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:cxn:cognit:v:1:y:2024:i:1:id:3
DOI: 10.63688/cognitivatech.v1.i1.3
Access Statistics for this article
More articles in CognitivaTech: IngenierÃa de Software Inteligente y Sistemas Adaptativos from Facultad Técnica de la Universidad Técnica de Oruro
Bibliographic data for series maintained by Editorial JOGB ().