Enforcing ASTD Access-Control Policies with WS-BPEL Processes in SOA Environments
Michel Embe Jiague,
Marc Frappier,
Frédéric Gervais,
Régine Laleau and
Richard St-Denis
Additional contact information
Michel Embe Jiague: Université de Sherbrooke, Canada, and Université Paris-Est Créteil Val-de-Marne, France
Marc Frappier: Université de Sherbrooke, Canada
Frédéric Gervais: Université Paris-Est Créteil Val-de-Marne, France
Régine Laleau: Université Paris-Est Créteil Val-de-Marne, France
Richard St-Denis: Université de Sherbrooke, Canada
International Journal of Systems and Service-Oriented Engineering (IJSSOE), 2011, vol. 2, issue 2, 37-59
Abstract:
Controlling access to the Web services of public agencies and private corporations depends primarily on specifying and deploying functional security rules to satisfy strict regulations imposed by governments, particularly in the financial and health sectors. This paper focuses on one aspect of the SELKIS and EB3SEC projects related to the security of Web-based information systems, namely, the automatic transformation of security rules into WS-BPEL (or BPEL, for short) processes. The former are instantiated from security-rule patterns written in a graphical notation, called ASTD that is close to statecharts. The latter are executed by a BPEL engine integrated into a policy decision point, which is a component of a policy enforcement manager similar to that proposed in the XACML standard.
Date: 2011
References: Add references at CitEc
Citations:
Downloads: (external link)
http://services.igi-global.com/resolvedoi/resolve. ... 018/jssoe.2011040103 (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:igg:jssoe0:v:2:y:2011:i:2:p:37-59
Access Statistics for this article
International Journal of Systems and Service-Oriented Engineering (IJSSOE) is currently edited by Wuhui Chen
More articles in International Journal of Systems and Service-Oriented Engineering (IJSSOE) from IGI Global
Bibliographic data for series maintained by Journal Editor ().