EconPapers    
Economics at your fingertips  
 

Access Control and Information Flow Control for Web Services Security

Saadia Kedjar, Abdelkamel Tari and Peter Bertok
Additional contact information
Saadia Kedjar: Department of Computer Science, Faculty of Exact Sciences, University of Bejaia, Bejaia, Algeria
Abdelkamel Tari: Faculty of Exact Sciences, University of Bejaia, Bejaia, Algeria
Peter Bertok: School of Computer Science and IT, RMIT University, Melbourne, Australia

International Journal of Information Technology and Web Engineering (IJITWE), 2016, vol. 11, issue 1, 44-76

Abstract: With the advancement of web services technology, security has become an increasingly important issue. Various security standards have been developed to secure web services at the transport and message level, but application level has received less attention. The security solutions at the application level focus on access control which cannot alone ensure the confidentiality and integrity of information. The solution proposed in this paper consists on a hybrid model that combines access control (AC) and information flow control (IFC). The AC mechanism uses the concept of roles and attributes to control user access to web services' methods. The IFC mechanism uses labels to control how the roles access to the system's objects and verify the information flows between them to ensure the information confidentiality and integrity. This manuscript describes the model, gives the demonstration of the IFC model safety, presents the modeling and implementation of the model and a case study.

Date: 2016
References: Add references at CitEc
Citations:

Downloads: (external link)
http://services.igi-global.com/resolvedoi/resolve. ... 18/IJITWE.2016010103 (application/pdf)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:igg:jitwe0:v:11:y:2016:i:1:p:44-76

Access Statistics for this article

International Journal of Information Technology and Web Engineering (IJITWE) is currently edited by Ghazi I. Alkhatib

More articles in International Journal of Information Technology and Web Engineering (IJITWE) from IGI Global
Bibliographic data for series maintained by Journal Editor ().

 
Page updated 2025-03-19
Handle: RePEc:igg:jitwe0:v:11:y:2016:i:1:p:44-76