Mediating Semantic Web Service Access using the Semantic Firewall
As the technical infrastructure to support Grid environments matures, attention should focus on providing dynamic access to services, whilst ensuring such access is appropriately monitored and secured. Access policies may be dynamic, whereby intra-organisational workflows define local knowledge that could be used to establish appropriate credentials necessary to access the desired service. We describe a typical Grid-based scenario that requires local semantic workflows that establish the appropriate security access, whilst global workflows define how external services are accessed. We present the Semantic Firewall, and the use of Process-based Access Control (PBAC) to mediate service access, and present OWL-S extensions that support additional PBAC access policies. Finally, a prototype implementation that validates this approach is presented.