A service-oriented approach to security - Concepts and issues

被引:4
|
作者
Bertino, Elisa [1 ]
Martino, Lorenzo D. [1 ]
机构
[1] Purdue Univ, W Lafayette, IN 47907 USA
关键词
D O I
10.1109/ISADS.2007.7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Various mechanisms for authentication and access control have been developed over time. Operating systems and DBMS implement such mechanisms and support quite rich access control models. A major limitation, however, of such mechanisms is that they are not extensible; thus whenever an application domain requires more sophisticated access controls or authentication, the applications must include logics for such controls. Such an approach leads to increased costs in application development and maintenance. For these reasons, models and mechanisms apt to separate those functions have emerged, also fostered by XML and Web services. At the same time, the need to drive the behaviour of security through clearly stated and machine-processable policies has fostered the development of various policy models and policy management mechanisms. A policy-based approach enhances flexibility, and reduces the application development costs. Changes to the access control or authentication requirements simply entail modifying the policies, without requiring changes to the applications. It is thus clear that an important approach to the problem of security is represented by the development of policy-based security services providing all functions for security management relevant to applications. Such an approach is particularly promising for applications organized according to the Service Oriented (SOA) paradigm. In this paper we discuss basic concepts of such an approach to security and we present a reference architectural framework. We discuss three relevant classes of security services, namely digital identity management services, authentication services, access control services, and outline research directions for each such class.
引用
收藏
页码:7 / +
页数:2
相关论文
共 50 条
  • [31] Service-oriented approach to collaborative visualization
    Wang, Haoxiang
    Brodlie, Ken
    Handley, James
    Wood, Jason
    PROCEEDINGS OF THE UK E-SCIENCE ALL HANDS MEETING 2006, 2006, : 241 - +
  • [32] An Approach for Verification in Service-Oriented Computing
    Chang, Soo Ho
    Chua, Fang Fang
    Kim, Soo Dong
    IEEE CONGRESS ON SERVICES 2008, PT I, PROCEEDINGS, 2008, : 575 - +
  • [33] A modelling approach to service-oriented architecture
    Zhang, Tao
    Ying, Shi
    Cao, Sheng
    Zhang, Jiankeng
    ENTERPRISE INFORMATION SYSTEMS, 2008, 2 (03) : 239 - 257
  • [34] Service-Oriented Approach for Internet of Things
    Moraes, Eduardo Cardoso
    COMPUTATIONAL SCIENCE - ICCS 2018, PT III, 2018, 10862 : 545 - 551
  • [35] Service-oriented approach to collaborative visualization
    Wang, H.
    Brodlie, K. W.
    Handley, J. W.
    Wood, J. D.
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2008, 20 (11): : 1289 - 1301
  • [36] Searching and Finding Concepts in Service-Oriented Enterprise Software
    Panchenko, Oleksandr
    Zeier, Alexander
    2008 IEEE SYMPOSIUM ON ADVANCED MANAGEMENT OF INFORMATION FOR GLOBALIZED ENTERPRISES, PROCEEDINGS, 2008, : 166 - 170
  • [37] A Service-Oriented Approach to Storage Backup
    Cheng, Hao
    Ho, Yao H.
    Hua, Kien A.
    Liu, Danzhou
    Xie, Fei
    Tsaur, Ynn-Pyng
    2008 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, VOL 2, 2008, : 413 - +
  • [38] Service-oriented concepts: bridging between managers and technologists
    Gulledge, Thomas
    Deller, Greg
    INDUSTRIAL MANAGEMENT & DATA SYSTEMS, 2009, 109 (1-2) : 5 - 15
  • [39] Probabilistic Approach to Service Commitment in Service-Oriented Systems
    Bannazadeh, Hadi
    Leon-Garcia, Alberto
    IEEE CONGRESS ON SERVICES 2008, PT I, PROCEEDINGS, 2008, : 273 - 278
  • [40] An approach for quality of service adaptation in service-oriented Grids
    Al-Ali, R
    Hafid, A
    Rana, O
    Walker, D
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2004, 16 (05): : 401 - 412