首页> 外文会议>International Conference on Service-Oriented Computing and Applications >SOABSE: An Approach to Realizing Business-Oriented Security Requirements with Web Service Security Policies
【24h】

SOABSE: An Approach to Realizing Business-Oriented Security Requirements with Web Service Security Policies

机译:Soabse:使用Web服务安全策略实现以业务为导向的安全要求的方法

获取原文
获取外文期刊封面目录资料

摘要

A critical issue in developing Web Service-based business applications is the realization of business-level security requirements with system-level security mechanisms using the WS-* standards. Current practice has primarily relied on the engineer's experience and lacks consistency and methodological support. This paper introduces an approach to Web Services security engineering called SOABSE, which systematically models, designs and implements security for a WS-based application from a given set of business-oriented security requirements. It includes 1) a stepwise process that systematically transforms business-level security requirements into system-level WS-* security policies, and relies on 2) a security realization model that maps business-level security objectives to WS-* security realization mechanisms and 3) a security deployment model that sets out the security-oriented Web Service deployment information. A prototype tool supporting the approach is also introduced.
机译:开发基于Web服务的业务应用程序的一个关键问题是使用WS-*标准使用系统级安全机制实现业务级安全要求。目前的实践主要依赖于工程师的经验,缺乏一致性和方法支持。本文介绍了一种名为SOABESE的Web服务安全工程方法,系统地模拟,设计和实现基于WS的应用程序的安全性,从给定的一套面向的业务安全要求。它包括1)一个逐步过程,系统地将业务级安全要求系统级转换为系统级WS-*安全策略,并依赖于2)将业务级安全目标映射到WS- *安全实现机制和3的安全实现模型)一种安全部署模型,其设置了面向安全的Web服务部署信息。还介绍了支持该方法的原型工具。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号