International Journal of Computer Applications |
Foundation of Computer Science (FCS), NY, USA |
Volume 42 - Number 6 |
Year of Publication: 2012 |
Authors: Hadiseh Seyyed Alipour, Mehdi Sabbari, Eslam Nazemi |
10.5120/5695-7469 |
Hadiseh Seyyed Alipour, Mehdi Sabbari, Eslam Nazemi . An Access Control Model for Web Services with Dynamic Separation of Duty Rules. International Journal of Computer Applications. 42, 6 ( March 2012), 6-13. DOI=10.5120/5695-7469
One of the most significant difficulties with developing Service-Oriented Architecture (SOA) involves meeting its security challenges. Access control is an important security mechanism for organizations to protect their resources in collaborative environments and processes. In these processes, shared resources are often used and there are complex relationships between activities and users, so the definition and administration of different security levels (tasks, users, resources, etc. ) is necessary. Different access control models and mechanisms have been proposed in recent years. However, under the new collaborative paradigm based on Web services and workflow technologies, some specific access control requirements should be addressed to support the various processes. In this paper, an access control model is proposed that considers the necessary elements to represent authentication, authorization and access control aspects in SOA environment. One of the underlined issues in this model is Separation of Duty (SoD) policy, which is widely considered to be a fundamental security principle for prevention of fraud and errors in information security.