Methodological model for authorization management in microservices-based applications

Authors

DOI:

https://doi.org/10.63688/cognitivatech.v1.i1.3

Keywords:

microservices, access control, ABAC, software security.

Abstract

The growing adoption of microservices-based architectures has transformed software development by enabling distributed, scalable, and loosely coupled systems; however, this evolution has also increased the complexity of access control management, particularly in terms of authorization. In this context, this research proposes a methodological approach to systematically integrate authorization policies into the software development lifecycle of microservice-based applications. The study follows a descriptive–analytical design structured into four stages: authorization requirements analysis, policy formalization, implementation within a distributed architecture, and validation through a case study. The results show that the use of the Attribute-Based Access Control (ABAC) model allows the definition of more precise and flexible rules compared to traditional role-based approaches, reducing redundancy and improving system adaptability. Additionally, separating authorization logic from business logic proved essential for enhancing maintainability and scalability, enabling policy modifications without affecting the services. The validation phase demonstrated that the early integration of authorization helps maintain consistency across requirements, design, and implementation, avoiding inconsistencies and rework. However, the findings also indicate that properly defining attributes requires a rigorous initial analysis. In conclusion, the proposed approach improves authorization management in microservices by providing a structured, coherent, and adaptable framework, contributing to the development of more secure and efficient systems.

References

Chandramouli, R., Butcher, Z., & Chetal, A. (2021). Attribute-based access control for microservices-based applications using a service mesh. NIST. https://doi.org/10.6028/NIST.SP.800-204B DOI: https://doi.org/10.6028/NIST.SP.800-204B

Devanbu, P., & Stubblebine, S. (2000). Software engineering for security: A roadmap. https://doi.org/10.1145/336512.336584 DOI: https://doi.org/10.1145/336512.336559

Ferraiolo, D., Kuhn, R., & Chandramouli, R. (2016). Role-based access control. Artech House. https://doi.org/10.1201/9781315369440 DOI: https://doi.org/10.1201/9781315369440

Ghotbi, S. H., & Fischer, B. (2013). Fine-grained role- and attribute-based access control for web applications. https://doi.org/10.1007/978-3-642-38709-8_12 DOI: https://doi.org/10.1007/978-3-642-45404-2_12

Goyal, V., Pandey, O., Sahai, A., & Waters, B. (2006). Attribute-based encryption for fine-grained access control. https://doi.org/10.1145/1180405.1180418 DOI: https://doi.org/10.1145/1180405.1180418

Hu, V. C., Kuhn, D. R., Ferraiolo, D. F., & Voas, J. (2015). Attribute-based access control. Computer, 48(2), 85–88. https://doi.org/10.1109/mc.2015.33 DOI: https://doi.org/10.1109/MC.2015.33

Hu, V. C., Kuhn, D. R., & Ferraiolo, D. F. (2018). Access control for emerging distributed systems. Computer, 51(10), 100–103. https://doi.org/10.1109/mc.2018.3971365 DOI: https://doi.org/10.1109/MC.2018.3971347

Khare, S., Thakur, P., Talwandi, N. S., & Yadav, V. (2024). Securing microservice architecture: Load balancing and role-based access control. https://doi.org/10.63503/j.ijaimd.2024.7 DOI: https://doi.org/10.1109/ICPEICES62430.2024.10719295

Madkaikar, G., Sural, S., Vaidya, J., & Atluri, V. (2024). Queuing theoretic analysis of dynamic attribute-based access control systems. https://doi.org/10.1007/978-3-031-65175-5_23 DOI: https://doi.org/10.1007/978-3-031-65175-5_23

Nehme, A., Jesus, V., Mahbub, K., & Abdallah, A. (2019). Fine-grained access control for microservices. https://doi.org/10.1007/978-3-030-18419-3_19 DOI: https://doi.org/10.1007/978-3-030-18419-3_19

Newman, S. (2015). Building microservices. O’Reilly Media.

Salehi, S. A., Han, R., Rudolph, C., & Grobler, M. (2023). DACP: Enforcing a dynamic access control policy in cross-domain environments. Computer Networks, 237, 110049. https://doi.org/10.1016/j.comnet.2023.110049 DOI: https://doi.org/10.1016/j.comnet.2023.110049

Sänger, N., & Abeck, S. (2023). User authorization in microservice-based applications. Software, 2(3), 400–426. https://doi.org/10.3390/software2030019 DOI: https://doi.org/10.3390/software2030019

Sandhu, R., Coyne, E., Feinstein, H., & Youman, C. (1996). Role-based access control models. https://doi.org/10.1109/2.485845 DOI: https://doi.org/10.1109/2.485845

Sandhu, R., & Samarati, P. (1994). Access control: Principle and practice. https://doi.org/10.1109/35.312842 DOI: https://doi.org/10.1109/35.312842

Schneider, M., Zieschinski, S., & Abeck, S. (2021). A test concept for microservice-based applications. https://doi.org/10.1109/sose52839.2021.00025 DOI: https://doi.org/10.1109/SOSE52839.2021.00025

Sidler, J., Braun, E., Schmitt, C., Schlachter, T., & Hagenmeyer, V. (2022). Microservice-based architecture for integration systems. https://doi.org/10.1007/978-3-030-88063-7_3 DOI: https://doi.org/10.1007/978-3-030-88063-7_3

Teerakanok, S., Uehara, T., & Inomata, A. (2021). Migrating to zero trust architecture: Reviews and challenges. https://doi.org/10.1155/2021/9947347 DOI: https://doi.org/10.1155/2021/9947347

Wang, H., Chen, Y., & Xu, Z. (2023). Decentralized access control for secure microservices cooperation with blockchain. ISA Transactions, 141, 44–51. https://doi.org/10.1016/j.isatra.2023.07.018 DOI: https://doi.org/10.1016/j.isatra.2023.07.018

Yuan, E., & Tong, J. (2005). Attribute-based access control (ABAC) for web services. https://doi.org/10.1109/icws.2005.25 DOI: https://doi.org/10.1109/ICWS.2005.25

Published

2024-07-22

Issue

Section

Original

How to Cite

Methodological model for authorization management in microservices-based applications. (2024). CognitivaTech: Ingeniería De Software Inteligente Y Sistemas Adaptativos, 1(1), 3. https://doi.org/10.63688/cognitivatech.v1.i1.3