Abstract
This paper presents a metamodel of a policy enforcement manager responsible for applying the rules defined in security policies with the aim to constraint the access to the functionalities and data of information systems. The metamodel is useful to derive platform-specific security models that provide the basis for the design and implementation of such managers for Web services as well as legacy information systems in various business sectors.
The research described in this paper was supported, in part, by the Natural Sciences and Engineering Research Council of Canada (NSERC) and the French National Research Agency (ANR).
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
Coatrieux, G., Embe Jiague, M., Morucci, S.: Implementation of Web services for security enforcement. Internal Technical Report, LACL, Université Paris-Est (2011)
Embe Jiague, M., Frappier, M., Gervais, F., Laleau, R., St-Denis, R.: Enforcing ASTD access-control policies with WS-BPEL processes in SOA environments. International Journal of Systems and Service-Oriented Engineering 2, 37–59 (2011)
Ferraiolo, D.F., Kuhn, D.R., Chandramouli, R.: Role-Based Access Control, 2nd edn. Artech House, Norwood (2007)
Frappier, M., Gervais, F., Laleau, R., Fraikin, B., St-Denis, R.: Extending statecharts with process algebra operators. Innovations in System and Software Engineering 4, 285–292 (2008)
Kalam, A.A.E., Baida, R.E., Balbiani, P., Benferhat, S., Cuppens, F., Deswarte, Y., Miège, A., Saurel, C., Trouessin, G.: Organization based access control. In: IEEE 4th International Workshop on Policies for Distributed Systems and Networks, pp. 120–131 (2003)
OASIS: eXtensible Access Control Markup Language (XACML) Version 2.0. OASIS (2005)
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2012 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Embe Jiague, M., Frappier, M., Gervais, F., Laleau, R., St-Denis, R. (2012). A Metamodel for the Design of Access-Control Policy Enforcement Managers: Work in Progress. In: Garcia-Alfaro, J., Lafourcade, P. (eds) Foundations and Practice of Security. FPS 2011. Lecture Notes in Computer Science, vol 6888. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-642-27901-0_17
Download citation
DOI: https://doi.org/10.1007/978-3-642-27901-0_17
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-642-27900-3
Online ISBN: 978-3-642-27901-0
eBook Packages: Computer ScienceComputer Science (R0)