首页> 外文会议> >Virtualised Trusted Computing Platform for Adaptive Security Enforcement of Web Services Interactions
【24h】

Virtualised Trusted Computing Platform for Adaptive Security Enforcement of Web Services Interactions

机译:用于Web服务交互的自适应安全实施的虚拟化可信计算平台

获取原文

摘要

Security enforcement framework is an important aspect of any distributed system. With new requirements imposed by SOA-based business models, adaptive security enforcement on the application level becomes even more important. Our work on the enforcement framework to date has resulted in a comprehensive middleware-based solution leveraging on web services technologies. However, potential merits of hardware-based solutions to further secure application exposure have not been considered so far. This paper describes a method for combining software resource level security features offered by Web Services technologies, with the hardware-based security mechanisms offered by Trusted Computing Platform and system virtualisation approaches. In particular, we propose trust-based architecture for protecting the enforcement middleware deployed at the policy enforcement endpoints of web and grid services. The main motivation is to additionally secure execution environment of the applications, by providing virtual machine level separation that maps from logical domains imposed by web services level enforcement policies.
机译:安全强制框架是任何分布式系统的一个重要方面。通过SOA的业务模型施加的新要求,应用程序级别的自适应安全实施变得更加重要。我们对迄今为止的执行框架的工作导致了一个基于中间件的基于中间件的解决方案,利用了Web服务技术。然而,到目前为止,基于硬件的解决方案的潜在优点是进一步安全应用曝光的潜在优点。本文介绍了一种组合Web服务技术提供的软件资源级安全功能的方法,具有由可信计算平台和系统虚拟化方法提供的基于硬件的安全机制。特别是,我们提出了基于信任的架构,用于保护在Web和网格服务的策略实施端点处部署的强制中间件。主要动机是通过提供从Web服务级执法策略所强加的逻辑域映射的虚拟机级别分离来等待应用程序的执行环境。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号