A service-oriented approach to security - Concepts and issues

被引:4
|
作者
Bertino, Elisa [1 ]
Martino, Lorenzo D. [1 ]
机构
[1] Purdue Univ, W Lafayette, IN 47907 USA
关键词
D O I
10.1109/ISADS.2007.7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Various mechanisms for authentication and access control have been developed over time. Operating systems and DBMS implement such mechanisms and support quite rich access control models. A major limitation, however, of such mechanisms is that they are not extensible; thus whenever an application domain requires more sophisticated access controls or authentication, the applications must include logics for such controls. Such an approach leads to increased costs in application development and maintenance. For these reasons, models and mechanisms apt to separate those functions have emerged, also fostered by XML and Web services. At the same time, the need to drive the behaviour of security through clearly stated and machine-processable policies has fostered the development of various policy models and policy management mechanisms. A policy-based approach enhances flexibility, and reduces the application development costs. Changes to the access control or authentication requirements simply entail modifying the policies, without requiring changes to the applications. It is thus clear that an important approach to the problem of security is represented by the development of policy-based security services providing all functions for security management relevant to applications. Such an approach is particularly promising for applications organized according to the Service Oriented (SOA) paradigm. In this paper we discuss basic concepts of such an approach to security and we present a reference architectural framework. We discuss three relevant classes of security services, namely digital identity management services, authentication services, access control services, and outline research directions for each such class.
引用
收藏
页码:7 / +
页数:2
相关论文
共 50 条
  • [1] A Service-Oriented approach to security - Concepts and issues
    Bertino, Elisa
    Martino, Lorenzo D.
    11TH IEEE INTERNATIONAL WORKSHOP ON FUTURE TRENDS OF DISTRIBUTED COMPUTING SYSTEMS, PROCEEDINGS, 2007, : 31 - +
  • [2] Security Issues of Service-Oriented Middleware
    Al-Jaroodi, Jameela
    Al-Dhaheri, Alyaziyah
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2011, 11 (01): : 153 - 160
  • [3] Investigation of security issues for service-oriented network architecture
    Rudra, Bhawana
    Vyas, Om Prakash
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (10) : 1025 - 1039
  • [4] A service-oriented approach for assessing infrastructure security
    Masera, Marcelo
    Fovino, Igor Nai
    CRITICAL INFRASTRUCTURE PROTE CTION, 2008, 253 : 367 - 379
  • [5] Service-oriented approach to visualize IT security performance metrics
    Martin, Clemens
    Refai, Mustapha
    TRUST MANAGEMENT, 2007, 238 : 403 - +
  • [6] Security in Service-oriented Grid
    Goranova, R.
    APPLICATIONS OF MATHEMATICS IN ENGINEERING AND ECONOMICS '34, 2008, 1067 : 541 - 548
  • [7] Concepts for service-oriented business thinking
    Nayak, Nitin
    Nigam, Anil
    Sanz, Jorge
    Marston, David
    Flaxer, David
    2006 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, 2006, : 357 - +
  • [8] Security modeling for service-oriented systems using security pattern refinement approach
    Memon, Mukhtiar
    Menghwar, Gordhan D.
    Depar, Mansoor H.
    Jalbani, Akhtar A.
    Mashwani, Waqar M.
    SOFTWARE AND SYSTEMS MODELING, 2014, 13 (02): : 549 - 572
  • [9] Security modeling for service-oriented systems using security pattern refinement approach
    Mukhtiar Memon
    Gordhan D. Menghwar
    Mansoor H. Depar
    Akhtar A. Jalbani
    Waqar M. Mashwani
    Software & Systems Modeling, 2014, 13 : 549 - 572
  • [10] ISSUES IN IT SERVICE-ORIENTED REQUIREMENTS ENGINEERING
    Lichtenstein, Sharman
    Nguyen, Lemai
    Hunter, Alexia
    AUSTRALASIAN JOURNAL OF INFORMATION SYSTEMS, 2005, 13 (01) : 176 - 191