loading...
Managing Trust in Active XML
Shanghai, China September 15-September 18
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/SCC.2004.1357988Services Computing, 2004 IEEE Interna ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Etienne Canaud, Lyon 1 University, France
Salima Benbernou, Lyon 1 University, France
Mohand-Sa? Hacid, Lyon 1 University, France
Active XML [The Active XML Team, http://www-rocq.inria.fr/gemo/gemo/projects/axml/] combines XML Data and service calls to allow a simple and powerful Web services implementation. Security in Active XML is currently handled by matching the structure of the received data with an XML Schema representing the allowed data (including service calls). This solution is not fully satisfactory in case of an open environment where the services do not often know or trust each other. Moreover, the strength of Active XML lies in its simple and dynamic structure, and the modified XML Schemas used for security matching can quickly limit the allowed services, or give too much freedom to services that should not be trusted. Given that the result of an Active XML service call is some Active XML data (that may include more service calls), Active XML data is recursive, thus involving more security concerns.
We propose a new framework based on the notion of Trust (Trusted Active XML) for handling security in Active XML. In this framework, "trusted" services' answers are not restricted to a specific data schema, while "untrusted" ones are prevented from performing some unwanted operations.
Citation:
Etienne Canaud, Salima Benbernou, Mohand-Sa? Hacid, "Managing Trust in Active XML," scc, pp.41-48, Services Computing, 2004 IEEE International Conference on (SCC'04), 2004
Usage of this product signifies your acceptance of the Terms of Use.