Access control for web services combining attributes with roles
Chunming Tang · Jisuanji gongcheng yu sheji · 2012
Based on the analysis of the access control requirements for web services,the limitation of current access control models for web services is pointed out,and a combining attributes with roles access control(ARBAC) model for web services and the architecture of the implementation is presented.The ARBAC model defines concepts of the access control for web services,and gives several judgment theorems.The ARBAC model could automatically produce the role set according to limitation requirements for users' attributes,accomplish the mapping among users,permissions and roles,and unify the access control for web services and data resources involved.