An architecture for unifying web services authentication and authorisation

UTSePress Research/Manakin Repository

Search UTSePress Research

Advanced Search


My Account

Show simple item record Steele, Robert en_US Tao, Wei en_US
dc.contributor.editor Benatallah, B; Casati, F; Traverso, P en_US 2009-11-09T02:45:45Z 2009-11-09T02:45:45Z 2005 en_US
dc.identifier 2005003377 en_US
dc.identifier.citation Steele Robert and Tao Wei 2005, 'An architecture for unifying web services authentication and authorisation', Springer, Berlin, Germany, pp. 582-587. en_US
dc.identifier.issn 3-540-30817-2 en_US
dc.identifier.other E1 en_US
dc.description.abstract Security issues are one of the major deterrents to Web Services adoption in mission critical applications and to the realization of the dynamic e- Business vision of Service Oriented Computing. Role Based Access Control (RBAC) is a common approach for authorization as it greatly simplifies complex authorization procedures in enterprise information systems. However, as most RBAC implementations rely on the manual setup of pre-defined user-ID and password combinations to identify the particular user, this makes it very hard to conduct dynamic e-Business as the service requestor and service provider must have prior knowledge of each other before the transaction. This paper proposes a new Web Services security architecture which unifies the authorization and authentication processes by extending current digital certificate technologies. It enables secure Web Service authorization decisions between parties even if previously unknown to each other and it also enhances the trustworthiness of service discovery en_US
dc.publisher Springer en_US
dc.relation.isbasedon en_US
dc.title An architecture for unifying web services authentication and authorisation en_US
dc.parent Service-Oriented computing ICSOC 2005 3rd International Conference Proceedings en_US
dc.journal.volume en_US
dc.journal.number en_US
dc.publocation Berlin, Germany en_US
dc.identifier.startpage 582 en_US
dc.identifier.endpage 587 en_US DVCRch.Institute for Information & Communication Technology en_US
dc.conference Verified OK en_US
dc.conference.location Amsterdam, Netherlands en_US
dc.for 080500 en_US
dc.personcode 010298 en_US
dc.personcode 10340026 en_US
dc.percentage 100 en_US Distributed Computing en_US
dc.classification.type FOR-08 en_US
dc.custom International Conference on Service Oriented Computing en_US 20011212 en_US
dc.location.activity Amsterdam, Netherlands en_US

Files in this item

This item appears in the following Collection(s)

Show simple item record