Full Text:   <2830>

CLC number: TP309

On-line Access: 2010-04-28

Received: 2009-04-02

Revision Accepted: 2009-07-29

Crosschecked: 2010-04-05

Cited: 4

Clicked: 7603

Citations:  Bibtex RefMan EndNote GB/T7714

-   Go to

Article info.
1. Reference List
Open peer comments

Journal of Zhejiang University SCIENCE C 2010 Vol.11 No.5 P.328-339

http://doi.org/10.1631/jzus.C0910186


Minimal role mining method for Web service composition


Author(s):  Chao Huang, Jian-ling Sun, Xin-yu Wang, Yuan-jie Si

Affiliation(s):  Department of Computer Science and Technology, Zhejiang University, Hangzhou 310027, China

Corresponding email(s):   hch@zju.edu.cn, sunjl@zju.edu.cn

Key Words:  Web service composition, Role base access control (RBAC), Role mining, Access control policy, Role mapping, Web service security


Chao Huang, Jian-ling Sun, Xin-yu Wang, Yuan-jie Si. Minimal role mining method for Web service composition[J]. Journal of Zhejiang University Science C, 2010, 11(5): 328-339.

@article{title="Minimal role mining method for Web service composition",
author="Chao Huang, Jian-ling Sun, Xin-yu Wang, Yuan-jie Si",
journal="Journal of Zhejiang University Science C",
volume="11",
number="5",
pages="328-339",
year="2010",
publisher="Zhejiang University Press & Springer",
doi="10.1631/jzus.C0910186"
}

%0 Journal Article
%T Minimal role mining method for Web service composition
%A Chao Huang
%A Jian-ling Sun
%A Xin-yu Wang
%A Yuan-jie Si
%J Journal of Zhejiang University SCIENCE C
%V 11
%N 5
%P 328-339
%@ 1869-1951
%D 2010
%I Zhejiang University Press & Springer
%DOI 10.1631/jzus.C0910186

TY - JOUR
T1 - Minimal role mining method for Web service composition
A1 - Chao Huang
A1 - Jian-ling Sun
A1 - Xin-yu Wang
A1 - Yuan-jie Si
J0 - Journal of Zhejiang University Science C
VL - 11
IS - 5
SP - 328
EP - 339
%@ 1869-1951
Y1 - 2010
PB - Zhejiang University Press & Springer
ER -
DOI - 10.1631/jzus.C0910186


Abstract: 
web service composition is a low cost and efficient way to leverage the existing resource and implementation. In current web service composition implementations, the issue of how to define the role for a new composite Web service has been little addressed. Adjusting the access control policy for a new composite Web service always causes substantial administration overhead from the security administrator. Furthermore, the distributed nature of Web service based applications makes traditional role mining methods obsolete. In this paper, we analyze the minimal role mining problem for web service composition, and prove that this problem is NP-complete. We propose a sub-optimal greedy algorithm based on the analysis of necessary role mapping for interoperation across multiple domains. Simulation shows the effectiveness of our algorithm, and compared to the existing methods, our algorithm has significant performance advantages. We also demonstrate the practical application of our method in a real agent based Web service system. The results show that our method could find the minimal role mapping efficiently.

Darkslateblue:Affiliate; Royal Blue:Author; Turquoise:Article

Reference

[1]Atluri, V., 2008. Panel on Role Engineering. Proc. 13th ACM Symp. on Access Control Models and Technologies, p.61-62.

[2]Carminati, B., Ferrari, E., Huang, P.C.K., 2005. Web Service Composition: A Security Perspective. Proc. Int. Workshop on Challenges in Web Information Retrieval and Integration, p.248-253.

[3]Colantonio, A., di Pietro, R., Ocello, A., 2008. A Cost-Driven Approach to Role Engineering. Proc. ACM Symp. on Applied Computing, p.2129-2136.

[4]Coyne, E.J., 1996. Role Engineering. Proc. 1st ACM Workshop on Role-Based Access Control, p.15-16.

[5]Dustdar, S., Schreiner, W., 2005. A survey on Web services composition. Int. J. Web Grid Serv., 1(1):1-30.

[6]Eid, M., Alamri, A., Saddik, A.E., 2008. A reference model for dynamic Web service composition systems. Int. J. Web Grid Serv., 4(2):149-168.

[7]Ene, A., Horne, W., Milosavljevic, N., Rao, P., Schreiber, R., Tarjan, R.E., 2008. Fast Exact and Heuristic Methods for Role Minimization Problems. Proc. 13th ACM Symp. on Access Control Models and Technologies, p.1-10.

[8]Essmayr, W., Probst, S., Weippl, E., 2004. Role-based access controls: status, dissemination, and prospects for generic security mechanisms. Electron. Comm. Res., 4(1/2):127-156.

[9]Ferraiolo, D.F., Sandhu, R., Gavrila, S., Kuhn, D.R., Chandramouli, R., 2001. Proposed NIST standard for role-based access control. ACM Trans. Inform. Syst. Secur., 4(3):224-274.

[10]Ferraiolo, D.F., Chandramouli, R., Ahn, G., Gavrila, S.I., 2003. The Role Control Center: Features and Case Studies. Proc. 8th ACM Symp. on Access Control Models and Technologies, p.12-20.

[11]Frank, M., Basin, D., Buhmann, J.M., 2008. A Class of Probabilistic Models for Role Engineering. Proc. 15th ACM Conf. on Computer and Communications Security, p.299-310.

[12]Garey, M.R., Johnson, D.S., 1979. Computers and Intractability: A Guide to the Theory of NP-Completeness. W.H. Freeman, New York.

[13]Goncalves, G., Poniszewska, M.A., 2008. Role engineering: from design to evolution of security schemes. J. Syst. Softw., 81(8):1306-1326.

[14]Huang, C., Sun, J., Wang, X., Si, Y., 2009. Selective Regression Test for Access Control System Employing RBAC. Proc. 3rd Int. Conf. and Workshops on Advances in Information Security and Assurance, p.70-79.

[15]Ko, J.M., Kim, C.O., Kwon, I., 2008. Quality-of-service oriented Web service composition algorithm and planning architecture. J. Syst. Softw., 81(11):2079-2090.

[16]Lécué, F., Delteil, A., Léger, A., 2008. Towards the Composition of Stateful and Independent Semantic Web Services. Proc. ACM Symp. on Applied Computing, p.2279-2285.

[17]Li, N., Tripunitara, M.V., 2006. Security analysis in role-based access control. ACM Trans. Inform. Syst. Secur., 9(4):391-420.

[18]Li, N., Byun, J., Bertino, E., 2007. A critique of the ANSI standard on role-based access control. IEEE Secur. Priv. Mag., 5(6):41-49.

[19]Molloy, I., Chen, H., Li, T., Wang, Q., Li, N., Bertino, E., Calo, S., Lobo, J., 2008. Mining Roles with Semantic Meanings. Proc. 13th ACM Symp. on Access Control Models and Technologies, p.21-30.

[20]Neumann, G., Strembeck, M., 2002. A Scenario-Driven Role Engineering Process for Functional RBAC Roles. Proc. 7th ACM Symp. on Access Control Models and Technologies, p.33-42.

[21]Park, J.S., Sandhu, R., Ahn, G., 2001. Role-based access control on the Web. ACM Trans. Inform. Syst. Secur., 4(1):37-71.

[22]Schaad, A., Moffett, J., Jacob, J., 2001. The Role-Based Access Control System of a European Bank: A Case Study and Discussion. Proc. 6th ACM Symp. on Access Control Models and Technologies, p.3-9.

[23]Schlegelmilch, J., Steffens, U., 2005. Role Mining with ORCA. Proc. 10th ACM Symp. on Access Control Models and Technologies, p.168-176.

[24]Sycara, K., Paolucci, M., Ankolekar, A., Srinivasan, N., 2003. Automated discovery, interaction and composition of semantic Web services. J. Web Semant., 1(1):27-46.

[25]Talib, M.A., Yang, Z., Ilyas, Q.M., 2006. A framework towards Web services composition modelling and execution. Int. J. Web Grid Serv., 2(1):25-49.

[26]Vaidya, J., Atluri, V., Guo, Q., 2007. The Role Mining Problem: Finding a Minimal Descriptive Set of Roles. Proc. 12th ACM Symp. on Access Control Models and Technologies, p.175-184.

[27]Vaidya, J., Atluri, V., Warner, J., Guo, Q., 2008. Role engineering via prioritized subset enumeration. IEEE Trans. Depend. Secur., 99.

Open peer comments: Debate/Discuss/Question/Opinion

<1>

Please provide your name, email address and a comment





Journal of Zhejiang University-SCIENCE, 38 Zheda Road, Hangzhou 310027, China
Tel: +86-571-87952783; E-mail: cjzhang@zju.edu.cn
Copyright © 2000 - 2024 Journal of Zhejiang University-SCIENCE