A User-oriented Multi-service Access Control System
نویسندگان
چکیده
Web-based services have become a major commodity. As an increasing number of ISPs make available an even more increasing number of remote services, security becomes a major concern in order to accomplish a fair exchange of commodities in insecure environments. An exchange of services, in order to be fair and secure, usually involves the service provider, the service requestor and a trusted third party on whose impartiality both rely. In order to provide and receive secure web-based services, trust can be accomplished by means of thorough identification and strong authentication of all the participants. The use of electronic credentials is one way of formal identification and authentication and the adoption of a unique worldwideaccepted digital credential stored in a smart card will provide a higher level of security while allowing total mobility with secure transactions over the web. While this adoption does not take place, the widespread use of digital credentials will inevitably lead to each service requestor having to be in possession of many smart cards just for storing the different electronic credentials needed for all the services he uses. We present a new approach for the use of smart cards as a basis for secure management of web-based services leading to the use of only one smart card per user in a perfectly transparent manner, thus contributing for a more generalized use of the technology.
منابع مشابه
Access and Mobility Policy Control at the Network Edge
The fifth generation (5G) system architecture is defined as service-based and the core network functions are described as sets of services accessible through application programming interfaces (API). One of the components of 5G is Multi-access Edge Computing (MEC) which provides the open access to radio network functions through API. Using the mobile edge API third party analytics applications ...
متن کاملAttribute-based Access Control for Cloud-based Electronic Health Record (EHR) Systems
Electronic health record (EHR) system facilitates integrating patients' medical information and improves service productivity. However, user access to patient data in a privacy-preserving manner is still challenging problem. Many studies concerned with security and privacy in EHR systems. Rezaeibagha and Mu [1] have proposed a hybrid architecture for privacy-preserving accessing patient records...
متن کاملArchitecting Dependable Access Control Systems for Multi-domain Computing Environments
Modern computing systems are built based on Service Oriented Architectures and are made up of multiple distributed components. They often span separate and autonomous domains of administration and involve dynamic collaboration. Resources and services are exposed as Web Services that are a natural choice for achieving interoperability in a heterogeneous computing environment. Access control syst...
متن کاملUser-defined Scenarios in Ubiquitous Environments: Creation, Execution Control and Sharing
Ubiquitous computing provides a dynamic access to different functionalities of networkable electronic devices. Whereas basic services have limited use, predefined complex services cannot encompass every end-user’s needs nor be adapted to a set of services that are dynamically discovered in an open environment. Alternatively, users need to be provided with means to express their requirements, ch...
متن کاملFrom Task Model to Multi-channel Access: Services Integration in the Ubi-learn Platform
The growing parallel development of mobile learning and of service oriented architecture approaches can modify the way to conceive, deploy and use learning management system. One of the main problems in combining these approaches is in the integration of learning services while taking into account the user interactions. The Ubi-Learn platform aims to provide an intermediation between services a...
متن کاملSmart City Reference Model: Interconnectivity for On-Demand User to Service Authentication
The Internet of Things and Services (IoTS) has encouraged the development of service provisioning systems in respect to Smart City topics. Most of them are operated as heterogeneous systems which limits end customers’ access and contradicts with IoTS principles. In this paper, we discuss and develop a reference model of an interconnected service marketplace ecosystem. The prototypical implement...
متن کامل