首页> 外文会议>Annual International Conference on Privacy, Security and Trust >Towards a BPEL model-driven approach for Web services security
【24h】

Towards a BPEL model-driven approach for Web services security

机译:迈向BPEL模型驱动的Web服务安全方法

获取原文

摘要

By handling the orchestration, composition and interaction of Web services, the Business Process Execution Language (BPEL) has gained tremendous interest. However, such process-based language does not assure a secure environment for Web services composition. The key solution cannot be seen as a simple embed of security properties in the source code of the business logic since the dynamism of the BPEL process will be affected when the security measures get updated. In this context, several approaches have emerged to tackle such issue by offering the ability to specify the security properties independently from the business logic based on policy languages. Nevertheless, these languages are complex, verbose and require programming expertise. Owing to these difficulties, specifying and the enforcing BPEL security policies become very tedious tasks. To mitigate these challenges, we propose in this paper, a novel approach that takes advantage of both the Unified Modeling Language (UML) and the Aspect Oriented Paradigm (AOP). By elaborating a UML extension mechanism, called UML Profile, our approach provides the users with model-based capabilities to specify aspects that enforce the required security policies. On the other hand, it offers a high level of flexibility when enforcing security hardening solutions in the BPEL process by exploiting the AOP approach. We illustrate our approach through an example of the dynamic generation and integration of model-based security aspects in a BPEL process.
机译:通过处理Web服务的编排,组成和互动,业务流程执行语言(BPEL)获得了巨大的兴趣。但是,这种基于过程的语言不确保Web服务组合的安全环境。由于BPEL进程的动态性,当BPEL进程的动态主动更新时,无法将关键解决方案视为业务逻辑源代码中的安全性质。在这种情况下,通过提供基于策略语言的业务逻辑独立地指定安全性属性,若干方法可以解决这些问题。尽管如此,这些语言都很复杂,冗长,需要编程专业知识。由于这些困难,指定和强制性BPEL安全政策成为非常繁琐的任务。为了减轻这些挑战,我们提出了一种利用统一建模语言(UML)和面向方向范例(AOP)的新方法。通过阐述称为UML配置文件的UML扩展机制,我们的方法为用户提供了基于模型的功能,以指定强制执行所需安全策略的方面。另一方面,通过利用AOP方法在BPEL过程中执行安全硬化解决方案时,它提供了高度的灵活性。我们通过BPEL过程中基于模型的安全方面的动态生成和集成的示例来说明我们的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号