【24h】

Secure Service Orchestration

机译:安全服务编排

获取原文
获取外文期刊封面目录资料

摘要

We present a framework for designing and composing services in a secure manner. Services can enforce security policies locally, and can invoke other services in a "call-by-contract" fashion. This mechanism offers a significant set of opportunities, each driving secure ways to compose services. We discuss how to correctly plan service orchestrations in some relevant classes of services and security properties. To this aim, we propose bot-h a core functional calculus for services and a graphical design language. The core calculus is called λ~(req). It features primitives for selecting and invoking services that respect given behavioural requirements. Critical code can be enclosed in security framings, with a possibly nested, local scope. These framings enforce safety properties on execution histories. A type and effect system over-approximates the actual run-time behaviour of services. Effects include the actions with possible security concerns, as well as information about which services may be selected at run-time. A verification step on these effects allows for detecting the viable plans that drive the selection of those services that match the security requirements on demand.
机译:我们提出了一种以安全方式设计和组合服务的框架。服务可以在本地实施安全策略,并且可以“按合同呼叫”的方式调用其他服务。该机制提供了大量机会,每种机会都在推动安全的服务组合方式。我们讨论如何在一些相关的服务和安全属性类中正确计划服务编排。为此,我们建议bot-h服务和图形设计语言的核心功能演算。核心演算称为λ〜(req)。它具有用于选择和调用符合给定行为要求的服务的原语。关键代码可以包含在安全框架中,并且可能嵌套本地范围。这些框架在执行历史上强制执行安全属性。类型和效果系统过于逼近服务的实际运行时行为。影响包括可能涉及安全问题的操作,以及有关在运行时可以选择哪些服务的信息。通过对这些影响的验证步骤,可以检测可行的计划,从而推动选择符合需求安全要求的服务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号