Policy and state based secure wrapper and its application to mobile agents

Alexander Binun, E. Gudes
{"title":"Policy and state based secure wrapper and its application to mobile agents","authors":"Alexander Binun, E. Gudes","doi":"10.1109/LAWEB.2003.1250278","DOIUrl":null,"url":null,"abstract":"Execution process in modern Web applications is usually represented as a partially ordered sequence of basic actions issued by a client (login, buy, exit, etc.; the login action usually precedes purchasing). Based on these actions, a finite automaton of fine-grained authorization checks, may be specified in a separate layer that is easily configurable for security needs of a particular application. In the Mobile case there may be two such state machines - one performing state-based authorization checks of the application execution process and the other performing such checks for the mobile agent execution process. Authorization checks of these machines may be both state-based and policy based, and the policies should distinguish between human clients and mobile agents cases. We develop the framework to specify and enforce finegrained state-based authorization checks of Web application execution, consisting of a Web browser (client) and a server. We adopt this framework to the mobile case so that state machines representing finegrained authorization checks of application and mobile agent execution are synchronized.","PeriodicalId":376743,"journal":{"name":"Proceedings of the IEEE/LEOS 3rd International Conference on Numerical Simulation of Semiconductor Optoelectronic Devices (IEEE Cat. No.03EX726)","volume":"7 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2003-11-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the IEEE/LEOS 3rd International Conference on Numerical Simulation of Semiconductor Optoelectronic Devices (IEEE Cat. No.03EX726)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/LAWEB.2003.1250278","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Execution process in modern Web applications is usually represented as a partially ordered sequence of basic actions issued by a client (login, buy, exit, etc.; the login action usually precedes purchasing). Based on these actions, a finite automaton of fine-grained authorization checks, may be specified in a separate layer that is easily configurable for security needs of a particular application. In the Mobile case there may be two such state machines - one performing state-based authorization checks of the application execution process and the other performing such checks for the mobile agent execution process. Authorization checks of these machines may be both state-based and policy based, and the policies should distinguish between human clients and mobile agents cases. We develop the framework to specify and enforce finegrained state-based authorization checks of Web application execution, consisting of a Web browser (client) and a server. We adopt this framework to the mobile case so that state machines representing finegrained authorization checks of application and mobile agent execution are synchronized.
基于策略和状态的安全包装器及其在移动代理中的应用
现代Web应用程序中的执行过程通常表示为客户端发出的部分有序的基本操作序列(登录、购买、退出等;登录操作通常先于购买)。基于这些操作,可以在单独的层中指定细粒度授权检查的有限自动机,该层易于配置,以满足特定应用程序的安全需求。在移动情况下,可能有两个这样的状态机——一个对应用程序执行过程执行基于状态的授权检查,另一个对移动代理执行过程执行此类检查。这些机器的授权检查可以是基于状态的,也可以是基于策略的,策略应该区分人类客户端和移动代理的情况。我们开发框架来指定和执行Web应用程序执行的基于状态的细粒度授权检查,该框架由Web浏览器(客户端)和服务器组成。我们将此框架应用于移动场景,以便表示应用程序和移动代理执行的细粒度授权检查的状态机同步。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信