Enforcing ASTD Access-Control Policies with WS-BPEL Processes in SOA Environments

Enforcing ASTD Access-Control Policies with WS-BPEL Processes in SOA Environments

Michel Embe Jiague, Marc Frappier, Frédéric Gervais, Régine Laleau, Richard St-Denis
DOI: 10.4018/jssoe.2011040103
(Individual Articles)
No Current Special Offers


Controlling access to the Web services of public agencies and private corporations depends primarily on specifying and deploying functional security rules to satisfy strict regulations imposed by governments, particularly in the financial and health sectors. This paper focuses on one aspect of the SELKIS and EB3SEC projects related to the security of Web-based information systems, namely, the automatic transformation of security rules into WS-BPEL (or BPEL, for short) processes. The former are instantiated from security-rule patterns written in a graphical notation, called ASTD that is close to statecharts. The latter are executed by a BPEL engine integrated into a policy decision point, which is a component of a policy enforcement manager similar to that proposed in the XACML standard.
Article Preview

Expressing Security Rules With An Astd

In most security frameworks, a security policy is a combination of many security rules. Researchers and security practitioners (Basin, Burri, & Karjoth, 2009; Konopacki, Frappier, & Laleau, 2010a, 2010b; Yao, Moody, & Bacon, 2001) have considered the following categories for security rules:

  • Permission which authorizes actions to be executed;

  • Prohibition which forbids actions to be executed;

  • Separation of duty which expresses the fact that a set of tasks cannot be executed by the same users or roles;

  • Obligation which forces a user to perform an action sometime in the future after he has performed a specific action. In other words, two distinct actions must be performed by the same user.

Complete Article List

Search this Journal:
Volume 13: 1 Issue (2024): Forthcoming, Available for Pre-Order
Volume 12: 2 Issues (2022): 1 Released, 1 Forthcoming
Volume 11: 2 Issues (2021)
Volume 10: 2 Issues (2020)
Volume 9: 2 Issues (2019)
Volume 8: 4 Issues (2018)
Volume 7: 4 Issues (2017)
Volume 6: 4 Issues (2016)
Volume 5: 4 Issues (2015)
Volume 4: 4 Issues (2014)
Volume 3: 4 Issues (2012)
Volume 2: 4 Issues (2011)
Volume 1: 4 Issues (2010)
View Complete Journal Contents Listing