Dissertation > Excellent graduate degree dissertation topics show
Research of Role-based Web Services Security Policy
Author: SunCuiCui
Tutor: ZhangYongSheng
School: Shandong Normal University
Course: Applied Computer Technology
Keywords: Web Services RBAC Attribute - based access control Authorize Entrust
CLC: TP393.08
Type: Master's thesis
Year: 2011
Downloads: 54
Quote: 1
Read: Download Dissertation
Abstract
|
The development of network information technology makes the concept of service-oriented architecture SOA (Service-Oriented Architecture) was put out. SOA can be seen as a component model, which can be organized into different functional units dispersed enterprise application can share standards-based service, when the business needs, these services can quickly be combined and reused to enterprise-specific tasks. SOA has loosely coupled, reusable, standardized service interface, developed high efficiency, fast response advantages, its scope of application is more and more widely. SOA complexity and interface diversity has its security management has become more complex. In this case, the Web service, the Web Services to solve the various problems faced by the SOA provides an effective program, a new technology to implement SOA. Simply put, Web services is a development model, it can be as \application integration problems. Web services rendered safe booming soon shows itself, therefore it is particularly important to study the Web services security policy. In general, Web services security policy covering at least three aspects: authentication policy, access control and privacy policies, including access control as an important element in the security technology faces enormous challenges. Traditional access control models have been unable to meet the demand in the Web services environment, discretionary access control model DAC due to grant permission autonomy, it is difficult to access permissions given out control; principle of mandatory access control model MAC is in strict accordance with the level of security access authorization, the lack of flexibility; role-based access control model RBAC although relatively flexible, easy to rights management, but because the roles are static and can not adapt to the changing Web services environment requirements, but does not have the fine access control granularity; This article studies the application of the attribute-based access control model ABAC meet the requirements in accordance with the attributes of the related entities to participate in decision-making whether to authorize a finer granularity of access control, and has a highly dynamic and flexibility. In this paper, the advantages of RBAC and ABAC model for the shortcomings of traditional access control model, Web Services role-based access control model for in-depth research. Thesis research and innovation are mainly the following aspects: 1. Discusses the concept of Web Services and related technologies, Web Services architecture and characteristics of the Web Services core SOAP, WSDL, UDDI, analysis, discussion Web Services Security technical specifications, used more often several access control model to analyze and do a comparison. 2 proposed a model R-ABAC model of access control based on roles and attributes of the model papers have been published in the journal \In-depth analysis of role-based access control and attribute-based access control based on the proposed R-ABAC model, access control and attribute access control advantages of the model through an integrated role, attributes the introduction of role-based access control, role attributes equally as the basis of the authorization decision, first when making authorization to verify the role of the user, the factors to be considered only when the user's role to access resources only attribute meets the requirements, thus forming a dual access control. The model has a higher level of security and flexibility, can effectively conserve system resources but also more fine-grained control of user access, and therefore able to adapt to the changing requirements of the Web Services environment. 3. Authorize a user-level role model, see Journal of the model papers have been published in the journal \The model is on the basis of a detailed analysis of the study authorization model, through the analysis of the advantages and disadvantages of each authorization model. The model is divided on the user's role is not only based on the user's identity, but a variety of integrated user attribute factors of user attribute classification, different attribute levels corresponding to different delegate roles which correspond to different access privileges to the user for access control purposes, a role authorization model based on attribute. 4 roles and property-based access control model R-ABAC model to achieve application. The simple design architecture student information management system, and R-ABAC model which analyze the function and application.
|
Related Dissertations
- Public service-oriented architecture -based information systems in the new rural information construction in applied research,TP393.09
- Ontology -based Semantic Web service matching and composition method,TP393.09
- A Design and Implementation of Single Sign-on System Based on the Improved RBAC Model and CAS,TP311.52
- The Research and Implementation of OA System Based on SOA and Workflow,TP311.52
- Design and Implementation on Data Exchange of Electronic Supervising System of Governmental Examining and Approval,TP311.52
- Master’s Thesis in Engineering,TN929.5
- Research and Implementation of the Techniques of Embedded Network Video Applications,TP368.1
- Enterprise Service Bus Based Information Integration System for Die & Mold Enterprises,TP311.52
- Research and Implementation of Automated Monitoring Information System for Soil-Water Conservation,TP311.52
- Management personnel and technical personnel to the problem of transition,F272.92
- Based on Web Service Online Examination Management System Research and Implementation,TP311.52
- For cross-border exchange of information visualization analysis of access control policy,TP393.08
- CAS-based identity management system design Petrochemical Institute,TP315
- Analysis on the Influencing Factors of Empowerment for the Patients with Diabetics and the Impact of Empowerment on Self-care Behaviors and Metabolic Indicators,R473.5
- The Design and Implement of Service Oriented Cross Domain Access Control System,TP273
- BPEL engine and dynamic recovery mechanisms Research and Implementation,TP393.09
- The Design and Implementation of a Stateful Web Services Container,TP393.09
- Design and Implement of SIngle Sign-on System Based Upon Certificate,TP393.08
- The Research on Fault-Tolerant Method of Web Services Composition,TP393.09
- Design and Implementation of Elective System Based on ASP. NET for High School’s New Courses,TP311.52
- Based on SDA architecture construction industry project management applied research,TP311.52
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|