A service-oriented approach to security - Concepts and issues

被引:4
|
作者
Bertino, Elisa [1 ]
Martino, Lorenzo D. [1 ]
机构
[1] Purdue Univ, W Lafayette, IN 47907 USA
关键词
D O I
10.1109/ISADS.2007.7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Various mechanisms for authentication and access control have been developed over time. Operating systems and DBMS implement such mechanisms and support quite rich access control models. A major limitation, however, of such mechanisms is that they are not extensible; thus whenever an application domain requires more sophisticated access controls or authentication, the applications must include logics for such controls. Such an approach leads to increased costs in application development and maintenance. For these reasons, models and mechanisms apt to separate those functions have emerged, also fostered by XML and Web services. At the same time, the need to drive the behaviour of security through clearly stated and machine-processable policies has fostered the development of various policy models and policy management mechanisms. A policy-based approach enhances flexibility, and reduces the application development costs. Changes to the access control or authentication requirements simply entail modifying the policies, without requiring changes to the applications. It is thus clear that an important approach to the problem of security is represented by the development of policy-based security services providing all functions for security management relevant to applications. Such an approach is particularly promising for applications organized according to the Service Oriented (SOA) paradigm. In this paper we discuss basic concepts of such an approach to security and we present a reference architectural framework. We discuss three relevant classes of security services, namely digital identity management services, authentication services, access control services, and outline research directions for each such class.
引用
收藏
页码:7 / +
页数:2
相关论文
共 50 条
  • [41] A Security Meta-Model for Service-oriented Architectures
    Menzel, Michael
    Meinel, Christoph
    2009 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, 2009, : 251 - 259
  • [42] Cross-Organizational Security - The Service-Oriented Difference
    Miede, Andre
    Nedyalkov, Nedislav
    Schuller, Dieter
    Repp, Nicolas
    Steinmetz, Ralf
    SERVICE-ORIENTED COMPUTING: ICSOC/SERVICE WAVE 2009 WORKSHOPS, 2010, 6275 : 72 - 81
  • [43] A security framework for developing service-oriented software architectures
    Rafe, Vahid
    Hosseinpouri, Ramin
    SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (17) : 2957 - 2972
  • [44] Forming a security certification enclave for service-oriented architectures
    Hepner, M.
    Gamble, M. T.
    Gamble, R.
    SCW 2006: IEEE SERVICES COMPUTING WORKSHOPS, PROCEEDINGS, 2006, : 148 - +
  • [45] Securing Enterprise Applications: Service-Oriented Security (SOS)
    Farkas, Csilla
    Huhns, Michael N.
    IEEE JOINT CONFERENCE ON E-COMMERCE TECHNOLOGY (CEC'08) AND ENTERPRISE COMPUTING, E-COMMERCE AND E-SERVICES (EEE'08), 2008, : 428 - 431
  • [46] Systematic security analysis for service-oriented software architectures
    Liu, Yanguo
    Traore, Issa
    ICEBE 2007: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2007, : 612 - 621
  • [47] Web Services Security Problem in Service-oriented Architecture
    Yue, Hua
    Tao, Xu
    INTERNATIONAL CONFERENCE ON APPLIED PHYSICS AND INDUSTRIAL ENGINEERING 2012, PT C, 2012, 24 : 1635 - 1641
  • [48] A Security Process for the Automotive Service-Oriented Software Architecture
    Puellen, Dominik
    Frank, Florian
    Christl, Marion
    Liu, Wuhao
    Katzenbeisser, Stefan
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2024, 73 (04) : 5036 - 5053
  • [49] Towards Security Awareness in Designing Service-oriented Architectures
    Nassar, Pascal Bou
    Badr, Youakim
    Biennier, Frederique
    Barbar, Kablan
    ICEIS: PROCEEDINGS OF THE 15TH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS - VOL 3, 2013, : 347 - 355
  • [50] Analysis of Security and Performance Aspects in Service-Oriented Architectures
    Rodrigues, Douglas
    Estrella, Julio C.
    Branco, Kalinka R. L. J. C.
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2011, 5 (01): : 13 - 30