Invention Grant
US08341694B2 Method and system for synchronized access control in a web services environment
有权
在Web服务环境中同步访问控制的方法和系统
- Patent Title: Method and system for synchronized access control in a web services environment
- Patent Title (中): 在Web服务环境中同步访问控制的方法和系统
-
Application No.: US11456190Application Date: 2006-07-08
-
Publication No.: US08341694B2Publication Date: 2012-12-25
- Inventor: Heather M. Hinton , Ivan M. Milman
- Applicant: Heather M. Hinton , Ivan M. Milman
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Jeffrey S. LaBaw; David H. Judson
- Main IPC: G06F7/04
- IPC: G06F7/04

Abstract:
Access controls for a Web service (which controls are based on abstract WSDL definitions) are defined for a WSDL defined protected object space and, as such, are loosely coupled with the concrete WSDL binding derived from those definitions, preferably on a per binding level. This WSDL-defined POS is in turn loosely bound to a resource-specific protected object space definition. This loose coupling is leveraged to allow changes (e.g., updates) to the abstract WSDL binding's protected object space to be transitively applied to the application-specific protected object space. If appropriate, changes to the resource-specific protected object space may be applied to the WSDL's protected object space. Thus, according to the invention, the coupling may be one-way (typically, from the WSDL POS to the resource level POS) or two-way (from the WSDL POS to the resource level POS and vice versa). This technique ensures that different security policies are not applied unintentionally to the same resource (for example, one at the Web services entry level, and the other at the resource level). By synchronizing the protected object spaces in the manner described, neither the entity that deploys the application nor the security administrator need to be aware of the differences between the Web service request and the resource request.
Public/Granted literature
- US20080022362A1 METHOD AND SYSTEM FOR SYNCHRONIZED ACCESS CONTROL IN A WEB SERVICES ENVIRONMENT Public/Granted day:2008-01-24
Information query