首页> 外文会议>Engineering secure software and systems >Middleware Support for Complex and Distributed Security Services in Multi-tier Web Applications
【24h】

Middleware Support for Complex and Distributed Security Services in Multi-tier Web Applications

机译:多层Web应用程序中对复杂和分布式安全服务的中间件支持

获取原文
获取原文并翻译 | 示例

摘要

The security requirements of complex multi-tier web applications have shifted from simple localized needs, such as authentication or authorization, to physically distributed but actually aggregated services, such as end-to-end data protection, non-repudiation or patient consent management. Currently, there is no support for integrating complex security services in web architectures, nor are approaches from other architectural models easily portable. In this paper we present the architecture of a security middleware, aimed at providing a reusable solution bringing support for complex security requirements into the application architecture, while addressing typical web architecture challenges, such as the tiered model or the lack of sophisticated client-side logic. We both evaluate the security of the middleware and present a case study and prototype implementation, which show how the complexities of a web architecture can be dealt with while limiting the integration effort.
机译:复杂的多层Web应用程序的安全要求已经从简单的本地化需求(例如身份验证或授权)转变为物理分布但实际上是聚合的服务(例如端到端数据保护,不可否认性或患者同意管理)。当前,不支持将复杂的安全服务集成到Web体系结构中,也无法轻松移植其他体系结构模型中的方法。在本文中,我们介绍了安全中间件的体系结构,旨在提供可重用的解决方案,将对复杂安全要求的支持引入应用程序体系结构中,同时解决典型的Web体系结构挑战,例如分层模型或缺少复杂的客户端逻辑。我们都评估了中间件的安全性,并提供了一个案例研究和原型实现,它们显示了如何在限制集成工作的同时处理Web体系结构的复杂性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号