WO2006106010A1 - Method and system for implementing authorization policies for web services - Google Patents
Method and system for implementing authorization policies for web services Download PDFInfo
- Publication number
- WO2006106010A1 WO2006106010A1 PCT/EP2006/060108 EP2006060108W WO2006106010A1 WO 2006106010 A1 WO2006106010 A1 WO 2006106010A1 EP 2006060108 W EP2006060108 W EP 2006060108W WO 2006106010 A1 WO2006106010 A1 WO 2006106010A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- request
- authorization
- authorization policy
- web service
- user
- Prior art date
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/102—Entity profiles
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
Landscapes
- Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Information Transfer Between Computers (AREA)
- Storage Device Security (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
- Stored Programmes (AREA)
Abstract
Description
Claims
Priority Applications (5)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
JP2008504715A JP2008537823A (en) | 2005-04-06 | 2006-02-20 | Method, system, and computer program for realizing authorization policy for Web service (method and system for realizing authorization policy for Web service) |
EP06708390.7A EP1867126B1 (en) | 2005-04-06 | 2006-02-20 | Method and system for implementing authorization policies for web services |
CA2602101A CA2602101C (en) | 2005-04-06 | 2006-02-20 | Method and system for implementing authorization policies for web services |
CN2006800045966A CN101116311B (en) | 2005-04-06 | 2006-02-20 | Method and system for implementing authorization policies for web services |
IL186327A IL186327A (en) | 2005-04-06 | 2007-10-07 | Method and system for implementing authorization policies for web services |
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US10/907,577 US7657924B2 (en) | 2005-04-06 | 2005-04-06 | Method and system for implementing authorization policies for web services |
US10/907,577 | 2005-04-06 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2006106010A1 true WO2006106010A1 (en) | 2006-10-12 |
Family
ID=36228728
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/EP2006/060108 WO2006106010A1 (en) | 2005-04-06 | 2006-02-20 | Method and system for implementing authorization policies for web services |
Country Status (8)
Country | Link |
---|---|
US (1) | US7657924B2 (en) |
EP (1) | EP1867126B1 (en) |
JP (1) | JP2008537823A (en) |
CN (1) | CN101116311B (en) |
CA (1) | CA2602101C (en) |
IL (1) | IL186327A (en) |
TW (1) | TW200705929A (en) |
WO (1) | WO2006106010A1 (en) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2012501010A (en) * | 2008-06-26 | 2012-01-12 | アリババ・グループ・ホールディング・リミテッド | Method and service integration platform system for providing internet services |
Families Citing this family (29)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20070192344A1 (en) * | 2005-12-29 | 2007-08-16 | Microsoft Corporation | Threats and countermeasures schema |
US20070156420A1 (en) * | 2005-12-29 | 2007-07-05 | Microsoft Corporation | Performance modeling and the application life cycle |
US7890315B2 (en) | 2005-12-29 | 2011-02-15 | Microsoft Corporation | Performance engineering and the application life cycle |
US20070157311A1 (en) * | 2005-12-29 | 2007-07-05 | Microsoft Corporation | Security modeling and the application life cycle |
US7818788B2 (en) * | 2006-02-14 | 2010-10-19 | Microsoft Corporation | Web application security frame |
US7712137B2 (en) | 2006-02-27 | 2010-05-04 | Microsoft Corporation | Configuring and organizing server security information |
US20080083009A1 (en) * | 2006-09-29 | 2008-04-03 | Microsoft Corporation | Policy fault |
US20080098463A1 (en) * | 2006-10-20 | 2008-04-24 | Nokia Corporation | Access control for a mobile server in a communication system |
US20080244693A1 (en) * | 2007-03-28 | 2008-10-02 | Bea Systems, Inc. | Smart web services policy selection using machine learning |
US8775603B2 (en) | 2007-05-04 | 2014-07-08 | Sitespect, Inc. | Method and system for testing variations of website content |
US20080301758A1 (en) * | 2007-05-31 | 2008-12-04 | Microsoft Corporation | Distributed knowledge access control |
US8266118B2 (en) * | 2008-02-07 | 2012-09-11 | Microsoft Corporation | Automated access policy translation |
US8418222B2 (en) * | 2008-03-05 | 2013-04-09 | Microsoft Corporation | Flexible scalable application authorization for cloud computing environments |
US8196175B2 (en) * | 2008-03-05 | 2012-06-05 | Microsoft Corporation | Self-describing authorization policy for accessing cloud-based resources |
GB2458568B (en) * | 2008-03-27 | 2012-09-19 | Covertix Ltd | System and method for dynamically enforcing security policies on electronic files |
US20100042656A1 (en) * | 2008-08-18 | 2010-02-18 | Microsoft Corporation | Claim generation for testing claims-based applications |
CN101753606B (en) * | 2008-12-03 | 2013-01-09 | 北京天融信科技有限公司 | Method for realizing WEB reverse proxy |
US8650479B2 (en) * | 2009-08-05 | 2014-02-11 | International Business Machines Corporation | Guided attachment of policies in a service registry environment |
RU2541911C2 (en) * | 2010-07-30 | 2015-02-20 | Эксенчер Глоубл Сервисиз Лимитед | Intelligent system kernel |
US8726349B2 (en) * | 2010-11-24 | 2014-05-13 | Oracle International Corporation | Optimizing interactions between co-located processes |
US9589145B2 (en) | 2010-11-24 | 2017-03-07 | Oracle International Corporation | Attaching web service policies to a group of policy subjects |
US8635682B2 (en) | 2010-11-24 | 2014-01-21 | Oracle International Corporation | Propagating security identity information to components of a composite application |
US8650288B2 (en) | 2010-11-24 | 2014-02-11 | Oracle International Corporation | Runtime usage analysis for a distributed policy enforcement system |
US8650250B2 (en) | 2010-11-24 | 2014-02-11 | Oracle International Corporation | Identifying compatible web service policies |
US9021055B2 (en) | 2010-11-24 | 2015-04-28 | Oracle International Corporation | Nonconforming web service policy functions |
US8560819B2 (en) | 2011-05-31 | 2013-10-15 | Oracle International Corporation | Software execution using multiple initialization modes |
US8914843B2 (en) * | 2011-09-30 | 2014-12-16 | Oracle International Corporation | Conflict resolution when identical policies are attached to a single policy subject |
US9648040B1 (en) * | 2013-09-19 | 2017-05-09 | Amazon Technologies, Inc. | Authorization check using a web service request |
CN108418872A (en) * | 2018-02-12 | 2018-08-17 | 千禧神骅科技(成都)有限公司 | A kind of internet special train plateform system that the load balancing of easy extension multiple terminals is high |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20030204622A1 (en) * | 2002-04-26 | 2003-10-30 | International Business Machines Corporation | Dynamic invocation of web services |
US20040093515A1 (en) * | 2002-11-12 | 2004-05-13 | Microsoft Corporation | Cross platform network authentication and authorization model |
WO2004084522A1 (en) * | 2003-03-15 | 2004-09-30 | International Business Machines Corporation | Client web service access |
Family Cites Families (11)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US6918107B2 (en) * | 2001-07-02 | 2005-07-12 | Bea Systems, Inc. | Programming language extensions for processing data representation language objects and related applications |
US7603469B2 (en) * | 2002-01-15 | 2009-10-13 | International Business Machines Corporation | Provisioning aggregated services in a distributed computing environment |
CA2369797A1 (en) * | 2002-01-31 | 2003-07-31 | Bridgewater Systems Corporation | System and method for web service management |
US20030163513A1 (en) * | 2002-02-22 | 2003-08-28 | International Business Machines Corporation | Providing role-based views from business web portals |
US20040054690A1 (en) * | 2002-03-08 | 2004-03-18 | Hillerbrand Eric T. | Modeling and using computer resources over a heterogeneous distributed network using semantic ontologies |
US7549153B2 (en) * | 2002-07-22 | 2009-06-16 | Amberpoint, Inc. | Apparatus and method for content and context processing of web service traffic |
US7747856B2 (en) * | 2002-07-26 | 2010-06-29 | Computer Associates Think, Inc. | Session ticket authentication scheme |
US7200657B2 (en) * | 2002-10-01 | 2007-04-03 | International Business Machines Corporation | Autonomic provisioning of network-accessible service behaviors within a federated grid infrastructure |
US20030172110A1 (en) * | 2002-12-10 | 2003-09-11 | Oracle International Corporation | Methods and apparatus for invoking a document style server operation using an operation name in a SOAPAction header |
US7461166B2 (en) * | 2003-02-21 | 2008-12-02 | International Business Machines Corporation | Autonomic service routing using observed resource requirement for self-optimization |
US7757268B2 (en) * | 2003-07-25 | 2010-07-13 | Oracle International Corporation | Policy based service management |
-
2005
- 2005-04-06 US US10/907,577 patent/US7657924B2/en active Active
-
2006
- 2006-02-20 JP JP2008504715A patent/JP2008537823A/en active Pending
- 2006-02-20 CN CN2006800045966A patent/CN101116311B/en active Active
- 2006-02-20 CA CA2602101A patent/CA2602101C/en active Active
- 2006-02-20 EP EP06708390.7A patent/EP1867126B1/en active Active
- 2006-02-20 WO PCT/EP2006/060108 patent/WO2006106010A1/en not_active Application Discontinuation
- 2006-04-03 TW TW095111823A patent/TW200705929A/en unknown
-
2007
- 2007-10-07 IL IL186327A patent/IL186327A/en not_active IP Right Cessation
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20030204622A1 (en) * | 2002-04-26 | 2003-10-30 | International Business Machines Corporation | Dynamic invocation of web services |
US20040093515A1 (en) * | 2002-11-12 | 2004-05-13 | Microsoft Corporation | Cross platform network authentication and authorization model |
WO2004084522A1 (en) * | 2003-03-15 | 2004-09-30 | International Business Machines Corporation | Client web service access |
Non-Patent Citations (1)
Title |
---|
KROPIWIEC C D ET AL: "A framework for protecting web sevices with IPsec", EUROMICRO CONFERENCE, 2004. PROCEEDINGS. 30TH RENNES, FRANCE AUG. 31 - SEPT. 3, 2004, PISCATAWAY, NJ, USA,IEEE, 31 August 2004 (2004-08-31), pages 290 - 297, XP010723603, ISBN: 0-7695-2199-1 * |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2012501010A (en) * | 2008-06-26 | 2012-01-12 | アリババ・グループ・ホールディング・リミテッド | Method and service integration platform system for providing internet services |
Also Published As
Publication number | Publication date |
---|---|
US20060230430A1 (en) | 2006-10-12 |
JP2008537823A (en) | 2008-09-25 |
CN101116311B (en) | 2010-12-01 |
IL186327A (en) | 2011-08-31 |
IL186327A0 (en) | 2008-01-20 |
CA2602101A1 (en) | 2006-10-12 |
EP1867126B1 (en) | 2014-08-13 |
CA2602101C (en) | 2014-04-08 |
US7657924B2 (en) | 2010-02-02 |
CN101116311A (en) | 2008-01-30 |
TW200705929A (en) | 2007-02-01 |
EP1867126A1 (en) | 2007-12-19 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CA2602101C (en) | Method and system for implementing authorization policies for web services | |
CN101523403B (en) | Method and system for synchronized policy control in a web services environment | |
US7870596B2 (en) | Accessing network resources outside a security boundary | |
US8341694B2 (en) | Method and system for synchronized access control in a web services environment | |
US7797726B2 (en) | Method and system for implementing privacy policy enforcement with a privacy proxy | |
US8095658B2 (en) | Method and system for externalizing session management using a reverse proxy server | |
Singhal et al. | Guide to secure web services | |
US8533782B2 (en) | Access control | |
US8095963B2 (en) | Securing resource stores with claims-based security | |
EP1067457B1 (en) | Management of a communication network and the migration of mobile agents | |
US20170187705A1 (en) | Method of controlling access to business cloud service | |
US8832779B2 (en) | Generalized identity mediation and propagation | |
KR100621318B1 (en) | Method for managing access and use of resources by verifying conditions and conditions for use therewith | |
US20090178105A1 (en) | Reducing overhead associated with distributed password policy enforcement operations | |
US20110161332A1 (en) | Method and System for Policy Driven Data Distribution | |
US8505068B2 (en) | Deriving express rights in protected content | |
US10229280B2 (en) | System and method to protect a resource using an active avatar | |
EP2677712B1 (en) | Method, system and computer program for obtaining the level of user recognition of statements | |
Pirnau | The analysis of the. NET architecture security system | |
Tan et al. | A security architecture for a semantic grid registry | |
WG et al. | OGSI Authorization Requirements | |
Baker et al. | Conceptual Grid Authorization Framework and Classification | |
Siebenlist et al. | OGSA Authorization Requirements |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application | ||
WWE | Wipo information: entry into national phase |
Ref document number: 200680004596.6 Country of ref document: CN |
|
WWE | Wipo information: entry into national phase |
Ref document number: 2602101 Country of ref document: CA |
|
WWE | Wipo information: entry into national phase |
Ref document number: 2008504715 Country of ref document: JP |
|
WWE | Wipo information: entry into national phase |
Ref document number: 186327 Country of ref document: IL |
|
NENP | Non-entry into the national phase |
Ref country code: DE |
|
WWW | Wipo information: withdrawn in national office |
Ref document number: DE |
|
WWE | Wipo information: entry into national phase |
Ref document number: 2006708390 Country of ref document: EP |
|
WWE | Wipo information: entry into national phase |
Ref document number: 4981/CHENP/2007 Country of ref document: IN |
|
NENP | Non-entry into the national phase |
Ref country code: RU |
|
WWW | Wipo information: withdrawn in national office |
Ref document number: RU |
|
WWP | Wipo information: published in national office |
Ref document number: 2006708390 Country of ref document: EP |