An access control model for service composite

作者:Ji Gaofeng*; Tang Yong; Huang Fan; Wang Peng; Wu Guibin
来源:11th International Conference on Computer Supported Cooperative Work in Design, 2007-04-26 to 2007-04-28.

摘要

Business Process Execution Language for Web Services is a language, which can be used to define abstract and executable processes. It has became to be the defacto standard of Web Service composition. However, the security aspect of access control is explicitly mentioned to be outside the scope of BPEL. This paper focuses on the implementation of access controls in the BPEL-based process. The existing Task-Based Access Control model was extended. The definition of authorization unit was modified and new types of authorization units were added Moreover the mapping from the process defined by BPEL to TBAC model was implemented and an approach of using TBAC in BPEL was put forward. The future work was pointed out in the end of the paper.