loading...
A Flexible Function Menu Generator for Supporting Access Control in Web Applications
Singapore November 23-November 25
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/CW.2005.42005 International Conference on Cybe ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Kung Chen, National Chengchi University, Taipei, Taiwan
Chih-Shang Chang, Tung Nan Institute of Technology, Taipei, Taiwan
Most access control frameworks for Web application enforce the control along with the invocation of an application function. While effective for preventing unauthorized access, it also incurs certain runtime overhead and user inconvenience, for it is often possible to determine whether a particular function should be allowed without actually having to try to perform it. This paper presents a flexible function menu generator (F-menugen) that restricts user menus to functions that a user?s current access-privileges permit, and can thus support access control on the presentation tier to overcome those shortcomings. The menu structure and rules governing the functions accessible to a user are specified declaratively in an XML configuration file; the rules are based on user attributes, application-specific requirements, and certain contextual information. This scheme retains the advantages of administrative scalability that rolebased access control offers, yet provides the flexibility to specify more complex restrictions without actual coding.
Citation:
Kung Chen, Chih-Shang Chang, "A Flexible Function Menu Generator for Supporting Access Control in Web Applications," cw, pp.523-530, 2005 International Conference on Cyberworlds (CW'05), 2005
Usage of this product signifies your acceptance of the Terms of Use.