Methodological model for authorization management in microservices-based applications
DOI:
https://doi.org/10.63688/cognitivatech.v1.i1.3Keywords:
microservices, access control, ABAC, software security.Abstract
The growing adoption of microservices-based architectures has transformed software development by enabling distributed, scalable, and loosely coupled systems; however, this evolution has also increased the complexity of access control management, particularly in terms of authorization. In this context, this research proposes a methodological approach to systematically integrate authorization policies into the software development lifecycle of microservice-based applications. The study follows a descriptive–analytical design structured into four stages: authorization requirements analysis, policy formalization, implementation within a distributed architecture, and validation through a case study. The results show that the use of the Attribute-Based Access Control (ABAC) model allows the definition of more precise and flexible rules compared to traditional role-based approaches, reducing redundancy and improving system adaptability. Additionally, separating authorization logic from business logic proved essential for enhancing maintainability and scalability, enabling policy modifications without affecting the services. The validation phase demonstrated that the early integration of authorization helps maintain consistency across requirements, design, and implementation, avoiding inconsistencies and rework. However, the findings also indicate that properly defining attributes requires a rigorous initial analysis. In conclusion, the proposed approach improves authorization management in microservices by providing a structured, coherent, and adaptable framework, contributing to the development of more secure and efficient systems.References
Chandramouli, R., Butcher, Z., & Chetal, A. (2021). Attribute-based access control for microservices-based applications using a service mesh. NIST. https://doi.org/10.6028/NIST.SP.800-204B DOI: https://doi.org/10.6028/NIST.SP.800-204B
Devanbu, P., & Stubblebine, S. (2000). Software engineering for security: A roadmap. https://doi.org/10.1145/336512.336584 DOI: https://doi.org/10.1145/336512.336559
Ferraiolo, D., Kuhn, R., & Chandramouli, R. (2016). Role-based access control. Artech House. https://doi.org/10.1201/9781315369440 DOI: https://doi.org/10.1201/9781315369440
Ghotbi, S. H., & Fischer, B. (2013). Fine-grained role- and attribute-based access control for web applications. https://doi.org/10.1007/978-3-642-38709-8_12 DOI: https://doi.org/10.1007/978-3-642-45404-2_12
Goyal, V., Pandey, O., Sahai, A., & Waters, B. (2006). Attribute-based encryption for fine-grained access control. https://doi.org/10.1145/1180405.1180418 DOI: https://doi.org/10.1145/1180405.1180418
Hu, V. C., Kuhn, D. R., Ferraiolo, D. F., & Voas, J. (2015). Attribute-based access control. Computer, 48(2), 85–88. https://doi.org/10.1109/mc.2015.33 DOI: https://doi.org/10.1109/MC.2015.33
Hu, V. C., Kuhn, D. R., & Ferraiolo, D. F. (2018). Access control for emerging distributed systems. Computer, 51(10), 100–103. https://doi.org/10.1109/mc.2018.3971365 DOI: https://doi.org/10.1109/MC.2018.3971347
Khare, S., Thakur, P., Talwandi, N. S., & Yadav, V. (2024). Securing microservice architecture: Load balancing and role-based access control. https://doi.org/10.63503/j.ijaimd.2024.7 DOI: https://doi.org/10.1109/ICPEICES62430.2024.10719295
Madkaikar, G., Sural, S., Vaidya, J., & Atluri, V. (2024). Queuing theoretic analysis of dynamic attribute-based access control systems. https://doi.org/10.1007/978-3-031-65175-5_23 DOI: https://doi.org/10.1007/978-3-031-65175-5_23
Nehme, A., Jesus, V., Mahbub, K., & Abdallah, A. (2019). Fine-grained access control for microservices. https://doi.org/10.1007/978-3-030-18419-3_19 DOI: https://doi.org/10.1007/978-3-030-18419-3_19
Newman, S. (2015). Building microservices. O’Reilly Media.
Salehi, S. A., Han, R., Rudolph, C., & Grobler, M. (2023). DACP: Enforcing a dynamic access control policy in cross-domain environments. Computer Networks, 237, 110049. https://doi.org/10.1016/j.comnet.2023.110049 DOI: https://doi.org/10.1016/j.comnet.2023.110049
Sänger, N., & Abeck, S. (2023). User authorization in microservice-based applications. Software, 2(3), 400–426. https://doi.org/10.3390/software2030019 DOI: https://doi.org/10.3390/software2030019
Sandhu, R., Coyne, E., Feinstein, H., & Youman, C. (1996). Role-based access control models. https://doi.org/10.1109/2.485845 DOI: https://doi.org/10.1109/2.485845
Sandhu, R., & Samarati, P. (1994). Access control: Principle and practice. https://doi.org/10.1109/35.312842 DOI: https://doi.org/10.1109/35.312842
Schneider, M., Zieschinski, S., & Abeck, S. (2021). A test concept for microservice-based applications. https://doi.org/10.1109/sose52839.2021.00025 DOI: https://doi.org/10.1109/SOSE52839.2021.00025
Sidler, J., Braun, E., Schmitt, C., Schlachter, T., & Hagenmeyer, V. (2022). Microservice-based architecture for integration systems. https://doi.org/10.1007/978-3-030-88063-7_3 DOI: https://doi.org/10.1007/978-3-030-88063-7_3
Teerakanok, S., Uehara, T., & Inomata, A. (2021). Migrating to zero trust architecture: Reviews and challenges. https://doi.org/10.1155/2021/9947347 DOI: https://doi.org/10.1155/2021/9947347
Wang, H., Chen, Y., & Xu, Z. (2023). Decentralized access control for secure microservices cooperation with blockchain. ISA Transactions, 141, 44–51. https://doi.org/10.1016/j.isatra.2023.07.018 DOI: https://doi.org/10.1016/j.isatra.2023.07.018
Yuan, E., & Tong, J. (2005). Attribute-based access control (ABAC) for web services. https://doi.org/10.1109/icws.2005.25 DOI: https://doi.org/10.1109/ICWS.2005.25
Published
Issue
Section
License
Copyright (c) 2024 Daniel Oswaldo Ramírez Guevara (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.
The article is distributed under the Creative Commons Attribution 4.0 License. Unless otherwise stated, associated published material is distributed under the same licence.