Security Over Web Services Using Evidence Based Access Control

E. S. Shameem Sulthana, Dr. S. Kanmani


This work focus on using evidence for making access control decisions in present computing environments. These environments create new interaction scenarios that traditional access control approaches handle poorly. This approach views access control as the filtering of messages between communicating services. This work implements the evidence-based approach with a mechanism analogous to a network firewall, filtering messages going to and from a service.
The main goal of this work is it supports communication between parties in different trust domains, allow evidence associated with parties to be securely collected and evaluated for the purpose of allowing access to resources, create an ecosystem in which evidence providers can flourish.
This will describe the design of the evidence-based access models; discuss usage scenarios, and present preliminary results.
The results suggest that this approach is flexible enough to accommodate interesting present computing scenarios and efficient enough to implement on small devices.


Access Control, Evidence, Firewall, Security, Web Services.

