首页> 外文会议>2012 Tenth Annual International Conference on Privacy, Security and Trust >Towards a BPEL model-driven approach for Web services security
【24h】

Towards a BPEL model-driven approach for Web services security

机译:迈向BPEL模型驱动的Web服务安全性方法

获取原文
获取原文并翻译 | 示例

摘要

By handling the orchestration, composition and interaction of Web services, the Business Process Execution Language (BPEL) has gained tremendous interest. However, such process-based language does not assure a secure environment for Web services composition. The key solution cannot be seen as a simple embed of security properties in the source code of the business logic since the dynamism of the BPEL process will be affected when the security measures get updated. In this context, several approaches have emerged to tackle such issue by offering the ability to specify the security properties independently from the business logic based on policy languages. Nevertheless, these languages are complex, verbose and require programming expertise. Owing to these difficulties, specifying and the enforcing BPEL security policies become very tedious tasks. To mitigate these challenges, we propose in this paper, a novel approach that takes advantage of both the Unified Modeling Language (UML) and the Aspect Oriented Paradigm (AOP). By elaborating a UML extension mechanism, called UML Profile, our approach provides the users with model-based capabilities to specify aspects that enforce the required security policies. On the other hand, it offers a high level of flexibility when enforcing security hardening solutions in the BPEL process by exploiting the AOP approach. We illustrate our approach through an example of the dynamic generation and integration of model-based security aspects in a BPEL process.
机译:通过处理Web服务的编排,组合和交互,业务流程执行语言(BPEL)引起了极大的兴趣。但是,这种基于过程的语言不能确保Web服务组合的安全环境。关键解决方案不能被视为简单地将安全属性嵌入业务逻辑的源代码中,因为当更新安全措施时,BPEL流程的动态性将受到影响。在这种情况下,通过提供独立于基于策略语言的业务逻辑来指定安全属性的能力,已经出现了几种解决该问题的方法。但是,这些语言很复杂,冗长,并且需要编程专家。由于这些困难,指定和执行BPEL安全策略变得非常繁琐的任务。为了减轻这些挑战,我们在本文中提出了一种利用统一建模语言(UML)和面向方面的范式(AOP)的新颖方法。通过详细介绍称为UML Profile的UML扩展机制,我们的方法为用户提供了基于模型的功能,以指定可实施所需安全策略的方面。另一方面,当通过利用AOP方法在BPEL流程中实施安全强化解决方案时,它提供了高度的灵活性。我们通过在BPEL流程中动态生成和集成基于模型的安全方面的示例来说明我们的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号