<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>Iranian Society of Cryptology</PublisherName>
				<JournalTitle>The ISC International Journal of Information Security</JournalTitle>
				<Issn>2008-2045</Issn>
				<Volume>3</Volume>
				<Issue>2</Issue>
				<PubDate PubStatus="epublish">
					<Year>2012</Year>
					<Month>05</Month>
					<Day>19</Day>
				</PubDate>
			</Journal>
<ArticleTitle>A model for specification, composition and verification of access control policies and its application to web services</ArticleTitle>
<VernacularTitle></VernacularTitle>
			<FirstPage>103</FirstPage>
			<LastPage>120</LastPage>
			<ELocationID EIdType="pii">39190</ELocationID>
			
<ELocationID EIdType="doi">10.22042/isecure.2015.3.2.4</ELocationID>
			
			<Language>EN</Language>
<AuthorList>
<Author>
					<FirstName>Z.</FirstName>
					<LastName>Derakhshandeh</LastName>
<Affiliation></Affiliation>

</Author>
<Author>
					<FirstName>B.</FirstName>
					<LastName>Tork Ladani</LastName>
<Affiliation></Affiliation>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
			<History>
				<PubDate PubStatus="received">
					<Year>2010</Year>
					<Month>12</Month>
					<Day>18</Day>
				</PubDate>
			</History>
		<Abstract>Despite significant advances in the access control domain, requirements of new computational environments like web services still raise new challenges. Lack of appropriate method for specification of access control policies (ACPs), composition, verification and analysis of them have all made the access control in the composition of web services a complicated problem. In this paper, a new independent formal model called Constrained Policy Graph (CPG) for specification of ACPs and their composition as well as verification of conflict or incompatibility among the ACPs is represented. It is shown how CPG can be used in modeling and verification of web service composition ACPs. Also the application of CPG for modeling policies in BPEL processes -as the most common composition method for web services- is illustrated.</Abstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">Access Control Policy (ACP)</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Verification</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Web Service Composition</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">BPEL</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Constrained Policy Graph (CPG)</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://www.isecure-journal.com/article_39190_f4491fcc2896910ad60de6986f83b31c.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
