Fakultät für Informatik TU München - Fakultät für Informatik
Lehrstuhl III: Datenbanksysteme
Technische Universität München
Home  |  Personen  |  Forschung  |  Lehre  |  Sonstiges  | 

Security Engineering for Web Services

Motivation

Security is always in the center of concern of any distributed system. In the area of Web services, several new approaches exist, regarding authentication and authorization - among others WS-Security and follow-up standards, as well as SAML and XACML. The focus of our research work lies upon reliable and adaptable security engineering, especially authorization, for services that interact with databases, what applies to the predominant majority of nowadays e-services. Considering security for database systems, common authorization techniques are discretionary access control (DAC), mandatory access control (MAC) and role based access control (RBAC). Inconsistencies are likely to arise, in case the access control for a Web service is designed in an uncorrelated manner with regard to the  authorization policies of underlying databases. We developed an approach to bridge the gap between DBMS authorization and access control for Web services. A Web service policy is designed reliably, if its access control is supported by the policies of the respective database system(s). This relationship can be verified automatically. Current research topics are concerned with the distributed evaluation of policies. That means, privileges can be delegated to other entities, especially across administrative domains.
 

Research topics

  • adaption of service policies based on corresponding database policies
  • role based access control techniques for configuring access control
  • semi-automatic policy generation, depending on service specifications
  • distributed authorization

Current status

The project is based upon the ServiceGlobe system. The described techniques are implemented as a prototype realization. Currently, distributed policy enforcement is evaluated and further effort is made regarding the supported generation of services with respective authorization policies.

Documents

  • Stefan Seltzsam, Stephan Börzsönyi, and Alfons Kemper
    Security for Distributed E-Service Composition
    Proceedings of the 2nd International Workshop on Technologies for E-Services (TES'2001)
    pages 147-162, Rome, Italy, September 2001. Springer Verlag, LNCS 2193.

Current research topics
  • delegation of rights in Web service environments
  • automatic policy and service development

Related projects
People
Professor:
  • Alfons Kemper

  • Ph.D. Students:
  • Stefan Seltzsam
  • Martin Wimmer

  • Students:
  • Daniela Eberhardt
  • Pia Ehrnlechner
  • Armin Fischer
  • Franz Häuslschmid

  • Lehrstuhl für Datenbanksysteme
    Letzte Änderung: 25.05.2005 um 14:38:38