{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:53:39Z","timestamp":1750308819665,"version":"3.41.0"},"reference-count":32,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2011,7,1]],"date-time":"2011-07-01T00:00:00Z","timestamp":1309478400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000145","name":"Division of Information and Intelligent Systems","doi-asserted-by":"publisher","award":["IIS-0916614IIS-0811954"],"award-info":[{"award-number":["IIS-0916614IIS-0811954"]}],"id":[{"id":"10.13039\/100000145","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004271","name":"Sapienza Universit\u00e0 di Roma","doi-asserted-by":"publisher","award":["METROFARI 2008FARI 2010TESTMED"],"award-info":[{"award-number":["METROFARI 2008FARI 2010TESTMED"]}],"id":[{"id":"10.13039\/501100004271","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000181","name":"Air Force Office of Scientific Research","doi-asserted-by":"publisher","award":["FA9550-08-1-0265"],"award-info":[{"award-number":["FA9550-08-1-0265"]}],"id":[{"id":"10.13039\/100000181","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004963","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["EU-FP7-FET-1P-SecureChange"],"award-info":[{"award-number":["EU-FP7-FET-1P-SecureChange"]}],"id":[{"id":"10.13039\/501100004963","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Web"],"published-print":{"date-parts":[[2011,7]]},"abstract":"<jats:p>\n            With organizations increasingly depending on Web services to build complex applications, security and privacy concerns including the protection of access control policies are becoming a serious issue. Ideally, service providers would like to make sure that clients have knowledge of only portions of the access control policy relevant to their interactions to the extent to which they are entrusted by the Web service and without restricting the client\u2019s choices in terms of which operations to execute. We propose\n            <jats:sc>ACConv<\/jats:sc>\n            , a novel model for access control in Web services that is suitable when interactions between the client and the Web service are conversational and long-running. The conversation-based access control model proposed in this article allows service providers to limit how much knowledge clients have about the credentials specified in their access policies. This is achieved while reducing the number of times credentials are asked from clients and minimizing the risk that clients drop out of a conversation with the Web service before reaching a final state due to the lack of necessary credentials. Clients are requested to provide credentials, and hence are entrusted with part of the Web service access control policies, only for some specific\n            <jats:italic>granted conversations<\/jats:italic>\n            which are decided based on: (1) a level of trust that the Web service provider has vis-\u00e0-vis the client, (2) the operation that the client is about to invoke, and (3)\n            <jats:italic>meaningful conversations<\/jats:italic>\n            which represent conversations that lead to a final state from the current one. We have implemented the proposed approach in a software prototype and conducted extensive experiments to show its effectiveness.\n          <\/jats:p>","DOI":"10.1145\/1993053.1993055","type":"journal-article","created":{"date-parts":[[2011,7,21]],"date-time":"2011-07-21T13:27:09Z","timestamp":1311254829000},"page":"1-33","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["ACConv -- An Access Control Model for Conversational Web Services"],"prefix":"10.1145","volume":"5","author":[{"given":"Federica","family":"Paci","sequence":"first","affiliation":[{"name":"University of Trento"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Massimo","family":"Mecella","sequence":"additional","affiliation":[{"name":"SAPIENZA Universit\u00e0 di Roma"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mourad","family":"Ouzzani","sequence":"additional","affiliation":[{"name":"Qatar Computing Research Institute, Qatar Foundation"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Elisa","family":"Bertino","sequence":"additional","affiliation":[{"name":"Purdue University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2011,7]]},"reference":[{"volume-title":"Proceedings of Semantic Web Services. AAAI. http:\/\/www.daml.ecs.soton.ac.uk\/SSS-SWS04\/Papers.html.","author":"Agarwal S.","key":"e_1_2_1_1_1","unstructured":"Agarwal , S. , Sprick , B. , and Wortmann , S . 2004. Credential based access control for semantic web services . In Proceedings of Semantic Web Services. AAAI. http:\/\/www.daml.ecs.soton.ac.uk\/SSS-SWS04\/Papers.html. Agarwal, S., Sprick, B., and Wortmann, S. 2004. Credential based access control for semantic web services. In Proceedings of Semantic Web Services. AAAI. http:\/\/www.daml.ecs.soton.ac.uk\/SSS-SWS04\/Papers.html."},{"key":"e_1_2_1_2_1","unstructured":"Anderson A. 2007. Web services profile of XACML (WS-XACML) version 1.0 OASIS standard specification. http:\/\/www.oasis-open.org\/committees\/download.php\/24951\/xacml-3.0-profile-webservices-spec-v1-wd-10-en.pdf. Anderson A. 2007. Web services profile of XACML (WS-XACML) version 1.0 OASIS standard specification. http:\/\/www.oasis-open.org\/committees\/download.php\/24951\/xacml-3.0-profile-webservices-spec-v1-wd-10-en.pdf."},{"key":"e_1_2_1_3_1","series-title":"Lecture Notes in Computer Science.","volume-title":"Proceedings of the International Semantic Web Conference (ISWC)","author":"Ankolekar A.","unstructured":"Ankolekar , A. 2002. DAML-S: Web service description for the semantic web . In Proceedings of the International Semantic Web Conference (ISWC) . Lecture Notes in Computer Science. Ankolekar, A. 2002. DAML-S: Web service description for the semantic web. In Proceedings of the International Semantic Web Conference (ISWC). Lecture Notes in Computer Science."},{"key":"e_1_2_1_4_1","volume-title":"Proceedings of the 15th International Conference on Advanced Information Systems Engineering (CAiSE). Lecture Notes in Computer Science","volume":"2681","author":"Benatallah B.","unstructured":"Benatallah , B. , Casati , F. , Toumani , F. , and Hamadi , R . 2003. Conceptual modeling of Web service conversations . In Proceedings of the 15th International Conference on Advanced Information Systems Engineering (CAiSE). Lecture Notes in Computer Science , vol. 2681 . Springer. Benatallah, B., Casati, F., Toumani, F., and Hamadi, R. 2003. Conceptual modeling of Web service conversations. In Proceedings of the 15th International Conference on Advanced Information Systems Engineering (CAiSE). Lecture Notes in Computer Science, vol. 2681. Springer."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1142\/S0218843005001201"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.4018\/jwsr.2006070102"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.5555\/1009386.1010156"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.5555\/512756.512758"},{"key":"e_1_2_1_9_1","volume-title":"Proceedings of the 2nd International Semantic Web Conference (ISWC). Lecture Notes in Computer Science","volume":"2870","author":"Denker G.","unstructured":"Denker , G. , Kagal , L. , Finin , T. , Paolucci , M. , and Sycara , K . 2003. Security for DAML Web services: Annotation and matchmaking . In Proceedings of the 2nd International Semantic Web Conference (ISWC). Lecture Notes in Computer Science , vol. 2870 . Springer. Denker, G., Kagal, L., Finin, T., Paolucci, M., and Sycara, K. 2003. Security for DAML Web services: Annotation and matchmaking. In Proceedings of the 2nd International Semantic Web Conference (ISWC). Lecture Notes in Computer Science, vol. 2870. Springer."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSEA.2007.15"},{"volume-title":"Proceedings of the 13th Annual Network and Distributed System Security Symposium (NDSS).","author":"Frikken B.","key":"e_1_2_1_11_1","unstructured":"Frikken , B. , Li , J. , and Atallah , M. J . 2006. Trust negotiation with hidden credentials, hidden policies and policies cycles . In Proceedings of the 13th Annual Network and Distributed System Security Symposium (NDSS). Frikken, B., Li, J., and Atallah, M. J. 2006. Trust negotiation with hidden credentials, hidden policies and policies cycles. In Proceedings of the 13th Annual Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_2_1_12_1","unstructured":"Globus. 2011. Globus toolkit. http:\/\/www.globus.org\/toolkit\/. Globus . 2011. Globus toolkit. http:\/\/www.globus.org\/toolkit\/."},{"volume-title":"HandBook of Algorithms and Data Structures","author":"Gonnet G. H.","key":"e_1_2_1_13_1","unstructured":"Gonnet , G. H. and Baeza-Yates , R. 1991. HandBook of Algorithms and Data Structures . Addison-Wesley . Gonnet, G. H. and Baeza-Yates, R. 1991. HandBook of Algorithms and Data Structures. Addison-Wesley."},{"key":"e_1_2_1_14_1","unstructured":"Internet2. 2006. OpenSAML - an open source security assertion language toolkit. http:\/\/www.opensaml.org. Internet2 . 2006. OpenSAML - an open source security assertion language toolkit. http:\/\/www.opensaml.org."},{"key":"e_1_2_1_15_1","volume-title":"Rei: A policy specification language","author":"Kagal L.","year":"2002","unstructured":"Kagal , L. 2002 . Rei: A policy specification language . http:\/\/rei.umbc.edu\/. Kagal, L. 2002. Rei: A policy specification language. http:\/\/rei.umbc.edu\/."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2004.23"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10922-006-9057-2"},{"key":"e_1_2_1_18_1","unstructured":"Lawrance K. and Kaler C. 2006. Web services security: SOAP message security version 1.1 OASIS standard specification. http:\/\/www.oasis-open.org\/committees\/download.php\/16790\/wss-v1.1-spec-os-SOAPMessageSecurity.pdf. Lawrance K. and Kaler C. 2006. Web services security: SOAP message security version 1.1 OASIS standard specification. http:\/\/www.oasis-open.org\/committees\/download.php\/16790\/wss-v1.1-spec-os-SOAPMessageSecurity.pdf."},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180422"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2006.54"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1135777.1135818"},{"key":"e_1_2_1_22_1","unstructured":"Moses T. 2005. Extensible access control markup language (XACML) version 2.0 OASIS standard. http:\/\/docs.oasis-open.org\/xacml\/2.0\/access_control-xacml-2.0-core-spec-os.pdf. Moses T. 2005. Extensible access control markup language (XACML) version 2.0 OASIS standard. http:\/\/docs.oasis-open.org\/xacml\/2.0\/access_control-xacml-2.0-core-spec-os.pdf."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1016\/0020-0190(94)90047-7"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDEW.2006.154"},{"key":"e_1_2_1_25_1","unstructured":"Saltzer J. H. and Schroeder M. D. 1974. The protection of information in computer systems. Comm. ACM 340--352. Saltzer J. H. and Schroeder M. D. 1974. The protection of information in computer systems. Comm. ACM 340--352."},{"volume-title":"Proceedings of the Conference on Network and Distributing System Security (NDSS\u201901)","author":"Seamons K.","key":"e_1_2_1_26_1","unstructured":"Seamons , K. , Winslett , M. , and Yu , T . 2001. Limiting the disclosure of access control policies during automated trust negotiations . In Proceedings of the Conference on Network and Distributing System Security (NDSS\u201901) . Seamons, K., Winslett, M., and Yu, T. 2001. Limiting the disclosure of access control policies during automated trust negotiations. In Proceedings of the Conference on Network and Distributing System Security (NDSS\u201901)."},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/507711.507715"},{"volume-title":"Proceedings of the Logics for Concurrency. Structure versus Automata (Eighth Banff Higher Order Workshop)","author":"Stirling C.","key":"e_1_2_1_28_1","unstructured":"Stirling , C. 1996. Modal and temporal logics for processes . In Proceedings of the Logics for Concurrency. Structure versus Automata (Eighth Banff Higher Order Workshop) . F. Moller and G. M. Birtwistle Eds. Lecture Notes in Computer Science, vol. 1043 . Springer . Stirling, C. 1996. Modal and temporal logics for processes. In Proceedings of the Logics for Concurrency. Structure versus Automata (Eighth Banff Higher Order Workshop). F. Moller and G. M. Birtwistle Eds. Lecture Notes in Computer Science, vol. 1043. Springer."},{"key":"e_1_2_1_29_1","unstructured":"Sun. 2003. Sun\u2019s XACML implementation. http:\/\/sunxacml.sourceforge.net. Sun . 2003. Sun\u2019s XACML implementation. http:\/\/sunxacml.sourceforge.net."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1137\/0201010"},{"volume-title":"Proceedings of the IEEE International Conference on Services Computing (SCC). IEEE.","author":"Wonohoesodo R.","key":"e_1_2_1_31_1","unstructured":"Wonohoesodo , R. and Tari , Z . 2004. A role based access control for Web services . In Proceedings of the IEEE International Conference on Services Computing (SCC). IEEE. Wonohoesodo, R. and Tari, Z. 2004. A role based access control for Web services. In Proceedings of the IEEE International Conference on Services Computing (SCC). IEEE."},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/605434.605435"}],"container-title":["ACM Transactions on the Web"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1993053.1993055","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1993053.1993055","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T20:26:39Z","timestamp":1750278399000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1993053.1993055"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,7]]},"references-count":32,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2011,7]]}},"alternative-id":["10.1145\/1993053.1993055"],"URL":"https:\/\/doi.org\/10.1145\/1993053.1993055","relation":{},"ISSN":["1559-1131","1559-114X"],"issn-type":[{"type":"print","value":"1559-1131"},{"type":"electronic","value":"1559-114X"}],"subject":[],"published":{"date-parts":[[2011,7]]},"assertion":[{"value":"2007-04-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2010-11-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-07-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}