首页> 外文会议>IFIP/IEEE International Symposium on Integrated Network Management >Automated deployment and Aggregated access control for SOA composite applications
【24h】

Automated deployment and Aggregated access control for SOA composite applications

机译:用于SOA复合应用的自动部署和聚合访问控制

获取原文

摘要

Modeling, assembling, deploying and managing Composite Applications built using Service Oriented Architectures (SOA) present many interesting challenges. Among these challenges, we consider two: service deployment and security management for access control. In this application session, these challenges are explored in the context of a prototype banking application: "Jivaro". The Jivaro prototype has features such as automated and configurable business processes using BPEL and manual tasks, multi-tenancy using virtual portals, and security using LDAP. We focus on two specific management pain points: 1. the difficulty in deploying multiple SOA components into multiple target middleware containers, and 2. inconsistency in access control policies for multi-tier applications. For addressing the deployment issues, we present a real-world deployment scenario involving the use of ANT tasks and scripting interfaces. For addressing inconsistencies in access control policies, we present a solution using the XACML standard, a common authorization model developed as an extension of the Java Authorization Contract for Containers and a common policy store and policy administration point. We compare and contrast current access control policies for J2EE containers and databases with the proposed new common authorization model. We also compare separate access control policy stores versus the proposed solution for a common store. Our aggregated role based authorization model provides consistent access control policies that complement single sign-on and identity propagation schemes. This model also touches upon issues surrounding role and policy based management, specifically regarding the potential of combining security policy administrator roles for different tiers.
机译:使用服务面向架构(SOA)建立的建模,组装,部署和管理复合应用程序呈现许多有趣的挑战。在这些挑战中,我们考虑二:服务部署和访问控制的安全管理。在本申请会话中,在原型银行应用程序的背景下探讨了这些挑战:“Jivaro”。 Jivaro Prototype具有使用BPEL和手动任务,使用虚拟门户网站的多租户以及使用LDAP的安全性的自动和可配置的业务流程功能。我们专注于两个特定的管理痛点:1。将多个SOA组件部署到多个目标中间件容器中的困难,以及2.访问控制策略中的多层应用程序的不一致。为了解决部署问题,我们介绍了一个涉及使用Ant任务和脚本接口的真实部署方案。为了解决访问控制策略中的不一致,我们使用XACML标准呈现一个解决方案,该解决方案是作为集装箱和共同策略存储和策略管理点的Java授权合同的扩展开发的常用授权模型。我们将J2EE容器和数据库的对比当前访问控制策略与所提出的新常见授权模型进行比较。我们还比较单独的访问控制策略存储与共同商店的建议解决方案。我们的聚合角色的授权模型提供了补充单点登录和身份传播方案的一致访问控制策略。此模型还涉及围绕围绕基于角色和基于策略管理的问题,特别是关于与不同层的安全策略管理员角色相结合的潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号