{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,4]],"date-time":"2025-12-04T09:53:30Z","timestamp":1764842010120,"version":"build-2065373602"},"reference-count":29,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2017,9,30]],"date-time":"2017-09-30T00:00:00Z","timestamp":1506729600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Microservices offer a compelling competitive advantage for building data flow systems as a choreography of self-contained data endpoints that each implement a specific data processing functionality. Such a \u2018single responsibility principle\u2019 design makes them well suited for constructing scalable and flexible data integration and real-time data flow applications. In this paper, we investigate microservice based data processing workflows from a security point of view, i.e., (1) how to constrain data processing workflows with respect to dynamic authorization policies granting or denying access to certain microservice results depending on the flow of the data; (2) how to let multiple microservices contribute to a collective data-driven authorization decision and (3) how to put adequate measures in place such that the data within each individual microservice is protected against illegitimate access from unauthorized users or other microservices. Due to this multifold objective, enforcing access control on the data endpoints to prevent information leakage or preserve one\u2019s privacy becomes far more challenging, as authorization policies can have dependencies and decision outcomes cross-cutting data in multiple microservices. To address this challenge, we present and evaluate a workflow-oriented authorization framework that enforces authorization policies in a decentralized manner and where the delegated policy evaluation leverages feature toggles that are managed at runtime by software circuit breakers to secure the distributed data processing workflows. The benefit of our solution is that, on the one hand, authorization policies restrict access to the data endpoints of the microservices, and on the other hand, microservices can safely rely on other data endpoints to collectively evaluate cross-cutting access control decisions without having to rely on a shared storage backend holding all the necessary information for the policy evaluation.<\/jats:p>","DOI":"10.3390\/fi9040058","type":"journal-article","created":{"date-parts":[[2017,10,2]],"date-time":"2017-10-02T13:10:05Z","timestamp":1506949805000},"page":"58","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":19,"title":["Access Control with Delegated Authorization Policy Evaluation for Data-Driven Microservice Workflows"],"prefix":"10.3390","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6279-4430","authenticated-orcid":false,"given":"Davy","family":"Preuveneers","sequence":"first","affiliation":[{"name":"imec-DistriNet-KU Leuven, Celestijnenlaan 200A, B-3001 Heverlee, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wouter","family":"Joosen","sequence":"additional","affiliation":[{"name":"imec-DistriNet-KU Leuven, Celestijnenlaan 200A, B-3001 Heverlee, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2017,9,30]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"2787","DOI":"10.1016\/j.comnet.2010.05.010","article-title":"The Internet of Things: A Survey","volume":"54","author":"Atzori","year":"2010","journal-title":"Comput. Netw."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1492","DOI":"10.1109\/SURV.2013.010413.00207","article-title":"Survey of Context Provisioning Middleware","volume":"15","author":"Knappmeyer","year":"2013","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Preuveneers, D., and Berbers, Y. (2008). Internet of things: A context-awareness perspective. The Internet of Things: From RFID to the Next-Generation Pervasive Networked Systems, CRC Press.","DOI":"10.1201\/9781420052824-13"},{"key":"ref_4","first-page":"63","article-title":"SAMURAI: A batch and streaming context architecture for large-scale intelligent applications and environments","volume":"8","author":"Preuveneers","year":"2016","journal-title":"JAISE"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"171","DOI":"10.1007\/s11036-013-0489-0","article-title":"Big Data: A Survey","volume":"19","author":"Chen","year":"2014","journal-title":"Mob. Netw. Appl."},{"key":"ref_6","unstructured":"Zikopoulos, P., and Eaton, C. (2011). Understanding Big Data: Analytics for Enterprise Class Hadoop and Streaming Data, McGraw-Hill Osborne Media. [1st ed.]."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Toshniwal, A., Taneja, S., Shukla, A., Ramasamy, K., Patel, J.M., Kulkarni, S., Jackson, J., Gade, K., Fu, M., and Donham, J. (2014, January 22\u201327). Storm@Twitter. Proceedings of the 2014 ACM SIGMOD International Conference on Management of Data (SIGMOD \u201914), Snowbird, UT, USA.","DOI":"10.1145\/2588555.2595641"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Kulkarni, S., Bhagat, N., Fu, M., Kedigehalli, V., Kellogg, C., Mittal, S., Patel, J.M., Ramasamy, K., and Taneja, S. (June, January 31). Twitter Heron: Stream Processing at Scale. Proceedings of the 2015 ACM SIGMOD International Conference on Management of Data (SIGMOD \u201915), Melbourne, Australia.","DOI":"10.1145\/2723372.2742788"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Chen, G.J., Wiener, J.L., Iyer, S., Jaiswal, A., Lei, R., Simha, N., Wang, W., Wilfong, K., Williamson, T., and Yilmaz, S. (July, January 26). Realtime Data Processing at Facebook. Proceedings of the 2016 International Conference on Management of Data (SIGMOD \u201916), San Francisco, CA, USA.","DOI":"10.1145\/2882903.2904441"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Kiran, M., Murphy, P., Monga, I., Dugan, J., and Baveja, S.S. (November, January 29). Lambda Architecture for Cost-effective Batch and Speed Big Data Processing. Proceedings of the 2015 IEEE International Conference on Big Data (Big Data) (BIG DATA \u201915), Santa Clara, CA, USA.","DOI":"10.1109\/BigData.2015.7364082"},{"key":"ref_11","unstructured":"Kreps, J. (2017, August 16). Questioning the Lambda Architecture. Available online: https:\/\/www.oreilly.com\/ideas\/questioning-the-lambda-architecture."},{"key":"ref_12","unstructured":"Fowler, M., and Lewis, J. (2017, August 16). Microservices. Available online: https:\/\/martinfowler.com\/articles\/microservices.html."},{"key":"ref_13","unstructured":"Newman, S. (2015). Building Microservices, O\u2019Reilly Media, Inc.. [1st ed.]."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Preuveneers, D., Joosen, W., and Ilie-Zudor, E. (2017). Policy reconciliation for access control in dynamic cross-enterprise collaborations. Enterp. Inf. Syst., 1\u201321. Available online: http:\/\/dx.doi.org\/10.1080\/17517575.2017.1355985.","DOI":"10.1080\/17517575.2017.1355985"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Rahman, M.T., Querel, L.P., Rigby, P.C., and Adams, B. (2016, January 14\u201315). Feature Toggles: Practitioner Practices and a Case Study. Proceedings of the 13th International Conference on Mining Software Repositories (MSR \u201916), Austin, TX, USA.","DOI":"10.1145\/2901739.2901745"},{"key":"ref_16","unstructured":"Nygard, M. (2007). Release It!: Design and Deploy Production-Ready Software, ACM. Pragmatic Bookshelf."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Jajoda, S., and Mazumdar, C. (2015, January 16\u201320). Enforcing Separation of Duty in Attribute Based Access Control Systems. Proceedings of the 11th International Conference on Information Systems Security (ICISS 2015), Kolkata, India.","DOI":"10.1007\/978-3-319-26961-0"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"666","DOI":"10.1147\/sj.403.0666","article-title":"Separation of Duties for Access Control Enforcement in Workflow Environments","volume":"40","author":"Botha","year":"2001","journal-title":"IBM Syst. J."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"9","DOI":"10.1109\/2.241422","article-title":"Lattice-Based Access Control Models","volume":"26","author":"Sandhu","year":"1993","journal-title":"Computer"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1109\/35.312842","article-title":"Access control: Principle and practice","volume":"32","author":"Sandhu","year":"1994","journal-title":"IEEE Commun. Mag."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"38","DOI":"10.1109\/2.485845","article-title":"Role-Based Access Control Models","volume":"29","author":"Sandhu","year":"1996","journal-title":"Computer"},{"key":"ref_22","unstructured":"Jin, X., Krishnan, R., and Sandhu, R. (2012, January 11\u201313). A Unified Attribute-based Access Control Model Covering DAC, MAC and RBAC. Proceedings of the 26th Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy, DBSec 2012, Paris, France."},{"key":"ref_23","unstructured":"XACML-V3.0 (2017). eXtensible Access Control Markup Language (XACML) Version 3.0 Plus Errata 01. OASIS Standard incorporating Approved Errata, OASIS Open. Available online: http:\/\/docs.oasis-open.org\/xacml\/3.0\/errata01\/os\/xacml-3.0-core-spec-errata01-os-complete.pdf."},{"key":"ref_24","unstructured":"Shamir, A. (,  1984). Identity-based Cryptosystems and Signature Schemes. Proceedings of the CRYPTO 84 on Advances in Cryptology, Santa Barbara, CA, USA."},{"key":"ref_25","unstructured":"Gunther, N.J. (2007). Guerrilla Capacity Planning\u2014A Tactical Approach to Planning for Highly Scalable Applications and Services, Springer."},{"key":"ref_26","unstructured":"Wikipedia (2014, February 10). Universal Law of Computational Scalability\u2014Wikipedia, 2014. Available online: https:\/\/en.wikipedia.org\/wiki\/Neil_J._Gunther#Universal_Law_of_Computational_Scalability."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Heyman, T., Preuveneers, D., and Joosen, W. (2014, January 27\u201329). Scalability Analysis of the OpenAM Access Control System with the Universal Scalability Law. Proceedings of the 2014 International Conference on Future Internet of Things and Cloud (FiCloud), Barcelona, Spain.","DOI":"10.1109\/FiCloud.2014.89"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Preuveneers, D., and Joosen, W. (2015, January 13\u201317). SmartAuth: Dynamic Context Fingerprinting for Continuous User Authentication. Proceedings of the 30th Annual ACM Symposium on Applied Computing (SAC \u201915), Salamanca, Spain.","DOI":"10.1145\/2695664.2695908"},{"key":"ref_29","first-page":"12","article-title":"How to Use the HL7 Composite Security and Privacy Domain Analysis Model","volume":"3","author":"Blobel","year":"2015","journal-title":"Int. J. Biomed. Healthc."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/9\/4\/58\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T18:46:24Z","timestamp":1760208384000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/9\/4\/58"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,9,30]]},"references-count":29,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2017,12]]}},"alternative-id":["fi9040058"],"URL":"https:\/\/doi.org\/10.3390\/fi9040058","relation":{},"ISSN":["1999-5903"],"issn-type":[{"type":"electronic","value":"1999-5903"}],"subject":[],"published":{"date-parts":[[2017,9,30]]}}}