Title
Types for Workflow Access Control in Web Service Context
Abstract
Workflow provides a promising solution for organizations to achieve their business goals by interactions and collaborations between Web services. Access control is an important security mechanism to protect the resources to be only accessed by authorized users in such collaborative environments. In this paper, we aim at developing a method for formalizing and analyzing workflow access control in Web service context. To achieve this goal, we first present WSPI, Web Service Pi calculus, to formalize Web services and workflow processes. Based on WSPI, a type system is proposed to ensure that the specified TBAC policy is respected during system reductions. By subject reduction, the well-typed system can guarantee the system security and avoid access violations in run time.
Year
DOI
Venue
2009
10.1109/SERVICES-I.2009.78
SERVICES I
Keywords
Field
DocType
RESOURCE ACCESS,PI-CALCULUS,SYSTEMS
World Wide Web,Workflow technology,Computer science,Web modeling,Web application security,Web service,Workflow engine,Workflow,Workflow management system,WS-Policy
Conference
ISBN
Citations 
PageRank 
978-0-7695-3708-5
0
0.34
References 
Authors
0
2
Name
Order
Citations
PageRank
Yahui Lu1163.45
Li Zhang24110.80