Verification of access control in Web services designing
XU Hongb · Jisuanji yingyong yanjiu · 2010
This paper proposed a novel approach to determine at design time whether by a designing could be implemented based on their access control policies and credential disclosure policies. Model both Web services and Web services designing as transition systems and represent Web services credential disclosure policies as directed graphs. Then verify that all possible conversations of the Web services designing could be implemented by matching credential disclosure policies of the invoker Web service with the access control policy of the Web services being invoked. Proposed a resource release graph to enable this verification.