Fine-grain, end-to-end security for web service compositions

被引:0
|
作者
Singaravelu, Lenin [1 ]
Pu, Calton [1 ]
机构
[1] Georgia Inst Technol, Coll Comp, 801 Atlantic Dr, Atlanta, GA 30332 USA
来源
2007 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS | 2007年
关键词
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Web service composition introduces two research challenges to end-to-end integrity and confidentiality of information flow. First, component services need the ability to selectively read or modify information flows. Second, component web services may or may not be trusted by all participants in the same degree. Existing specifications such as WS-Security provide fine-grained signatures and encryption for pair-wise interactions, but insufficient support for end-to-end security properties in open environments. Using an electronic prescription application, we illustrate the need for an enhanced framework for providing end-to-end security properties. We then describe a fine-grained, security framework, called WS-FESec, that leverages WS-Security to support flexible preservation of end-to-end integrity and confidentiality in web service compositions. Finally, we discuss WS-FESec's support for the lattice model of secure information flow and show how it can be employed to preserve end-to-end security properties in the electronic prescriptions application.
引用
收藏
页码:212 / +
页数:2
相关论文
共 50 条
  • [21] End-to-End Security for Personal Telehealth
    Koster, Paul
    Asim, Muhammad
    Petkovic, Milan
    USER CENTRED NETWORKED HEALTH CARE, 2011, 169 : 621 - 625
  • [22] End-to-End Security for Enterprise Mashups
    Rosenberg, Florian
    Khalaf, Rania
    Duftler, Matthew
    Curbera, Francisco
    Austel, Paula
    SERVICE-ORIENTED COMPUTING - ICSOC 2009, PROCEEDINGS, 2009, 5900 : 389 - +
  • [23] End-to-end security for GSM users
    Rekha, AB
    Umadevi, B
    Solanke, Y
    Kolli, SR
    2005 IEEE INTERNATIONAL CONFERENCE ON PERSONAL WIRELESS COMMUNICATIONS, 2005, : 434 - 437
  • [25] End-to-end performance of web services
    Cremonesi, P
    Serazzi, G
    PERFORMANCE EVALUATION OF COMPLEX SYSTEMS: TECHNIQUES AND TOOLS: PERFORMANCE 2002 TUTORIAL LECTURES, 2002, 2459 : 158 - 178
  • [26] Integrating web server and network QoS to provide end-to-end service differentiation
    Tham, CK
    Subramaniam, VR
    10TH IEEE INTERNATIONAL CONFERENCE ON NETWORKS (ICON 2002), PROCEEDINGS, 2002, : 389 - 394
  • [27] A Hybrid Approach for Efficient Web Service Composition with End-to-End QoS Constraints
    Alrifai, Mohammad
    Risse, Thomas
    Nejdl, Wolfgang
    ACM TRANSACTIONS ON THE WEB, 2012, 6 (02)
  • [28] One Time Chat - A Toy End-to-End Encrypted Web Messaging Service
    Kaczynski, Kamil
    Glet, Michal
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY WORKSHOPS, PT II, ACNS 2024-AIBLOCK 2024, AIHWS 2024, AIOTS 2024, SCI 2024, AAC 2024, SIMLA 2024, LLE 2024, AND CIMSS 2024, 2024, 14587 : 183 - 187
  • [29] End-to-end WAN service availability
    Chandra, B
    Dahlin, M
    Gao, L
    Nayate, A
    USENIX ASSOCIATION PROCEEDINGS OF THE 3RD USENIX SYMPOSIUM ON INTERNET TECHNOLOGIES AND SYSTEMS, 2001, : 97 - 108
  • [30] End-to-End Service Support for Mashups
    Bouguettaya, Athman
    Nepal, Surya
    Sherchan, Wanita
    Zhou, Xuan
    Wu, Jemma
    Chen, Shiping
    Liu, Dongxi
    Li, Lily
    Wang, Hongbing
    Liu, Xumin
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2010, 3 (03) : 250 - 263