Achieving secure and flexible M-services through tickets
Article
Article Title | Achieving secure and flexible M-services through tickets |
---|---|
Article Category | Article |
Authors | Wang, Hua (Author), Zhang, Yanchun (Author), Cao, Jinli (Author) and Varadharajan, Vijay (Author) |
Journal Title | Systems, Man, and Cybernetics. Part A |
Journal Citation | 33 (6), pp. 697-708 |
Number of Pages | 12 |
Year | 2003 |
Digital Object Identifier (DOI) | https://doi.org/10.1109/TSMCA.2003.819917 |
Web Address (URL) | https://ieeexplore.ieee.org/document/1255581 |
Abstract | Web services via wireless technologies, mobile services (M-services), HTTP, and XML have become important for conducting business. W3C XML Protocol Working Group has been developing standard techniques such as Web Services Description Language (WSDL), simple object access protocol (SOAP), universal description discovery and integration (UDDI). However, at this stage, there is no standard technique for access control in M-services. This paper describes a secure and flexible access control scheme and protocol for M-services based on role based access control (RBAC). The access control architecture involves a Trusted Credential Center (TCC), a Trusted Authentication and Registration Center (TARC) and a secure ticket based mechanism for service access. Users and service providers register with the TARC and are authenticated. Based on this, tickets are issued by the TCC to users. Tickets carry authorization information needed for the requested services. In particular, we are able to specify access control polices based on roles. The protocols between the various entities in the model are protected using appropriate security mechanisms such as signatures which are used to verify correctness of the requested service, as well as to direct billing information to the appropriate user. Our architecture supports efficient authentication of users and service providers over different domains and provides a secure access model for services to users. Our model is also able to support anonymity of users. Only the TARC is able to identify misbehaving users. We believe that the proposed architecture forms a good basis for achieving a secure and flexible M-service system. |
Keywords | access control architecture, anonymity, RBAC, secure M-services, ticket based access control |
ANZSRC Field of Research 2020 | 350302. Business information management (incl. records, knowledge and intelligence) |
461009. Recordkeeping informatics | |
460401. Cryptography | |
Public Notes | Files associated with this item cannot be displayed due to copyright restrictions. |
Byline Affiliations | Department of Mathematics and Computing |
Victoria University | |
La Trobe University | |
Macquarie University |
https://research.usq.edu.au/item/9y5z5/achieving-secure-and-flexible-m-services-through-tickets
Download files
1862
total views384
total downloads2
views this month0
downloads this month