首页> 外文会议> >Automated deployment and Aggregated access control for SOA composite applications
【24h】

Automated deployment and Aggregated access control for SOA composite applications

机译:SOA组合应用程序的自动部署和聚合访问控制

获取原文

摘要

Modeling, assembling, deploying and managing Composite Applications built using Service Oriented Architectures (SOA) present many interesting challenges. Among these challenges, we consider two: service deployment and security management for access control. In this application session, these challenges are explored in the context of a prototype banking application: "Jivaro". The Jivaro prototype has features such as automated and configurable business processes using BPEL and manual tasks, multitenancy using virtual portals, and security using LDAP. We focus on two specific management pain points: 1. the difficulty in deploying multiple SOA components into multiple target middleware containers, and 2. inconsistency in access control policies for multi-tier applications. For addressing the deployment issues, we present a real-world deployment scenario involving the use of ANT tasks and scripting interfaces. For addressing inconsistencies in access control policies, we present a solution using the XACML standard, a common authorization model developed as an extension of the Java Authorization Contract for Containers and a common policy store and policy administration point. We compare and contrast current access control policies for J2EE containers and databases with the proposed new common authorization model. We also compare separate access control policy stores versus the proposed solution for a common store. Our aggregated role based authorization model provides consistent access control policies that complement single sign-on and identity propagation schemes. This model also touches upon issues surrounding role and policy based management, specifically regarding the potential of combining security policy administrator roles for different tiers.
机译:使用面向服务的体系结构(SOA)构建的组合应用程序的建模,组装,部署和管理提出了许多有趣的挑战。在这些挑战中,我们考虑两个:服务部署和用于访问控制的安全性管理。在本应用程序会议中,将在银行业务原型应用程序“ Jivaro”的上下文中探讨这些挑战。 Jivaro原型具有诸如使用BPEL和手动任务的自动化和可配置业务流程,使用虚拟门户网站的多租户以及使用LDAP的安全性等功能。我们关注两个特定的管理难题:1.难以将多个SOA组件部署到多个目标中间件容器中;以及2.多层应用程序的访问控制策略不一致。为了解决部署问题,我们提出了一个实际的部署方案,其中涉及到ANT任务和脚本接口的使用。为了解决访问控制策略中的不一致问题,我们提出了一种使用XACML标准的解决方案,一种作为Java容器授权协议的扩展而开发的通用授权模型以及通用策略存储和策略管理点。我们将J2EE容器和数据库的当前访问控制策略与建议的新通用授权模型进行比较和对比。我们还将比较单独的访问控制策略存储与针对通用存储的建议解决方案。我们基于角色的聚合授权模型提供了一致的访问控制策略,可补充单点登录和身份传播方案。该模型还涉及围绕角色和基于策略的管理的问题,特别是关于将安全策略管理员角色组合为不同层的潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号