首页> 外文会议>SETOP 2012 >Policy Chain for Securing Service Oriented Architectures
【24h】

Policy Chain for Securing Service Oriented Architectures

机译:保护服务导向架构的政策链

获取原文

摘要

Service Providers using Service Oriented Architecture in order to deliver in-house services as well as on-demand and cloud services have to deal with two interdependent challenges: (1) to achieve, maintain and prove compliance with security requirements stemming from internal needs, 3rd party demands and international regulations and (2) to manage requirements, policies and security configuration in a cost-efficient manner. The deficiencies of current processes and tools force these service providers to trade off profitability against security and compliance. This paper summarizes a novel approach of a policy chain, which links high-level, abstract and declarative security policies on one side and low-level, imperative, and technical security configuration settings on the other side. The paper describes an architecture linking several applications and models via state-machines in order to provide a toolset supporting service providers to build such a holistic policy chain at design time, and to maintain and leverage it during system operation.
机译:服务提供商使用面向服务的架构,以便提供内部服务以及点心和云服务必须处理两个相互依存的挑战:(1)实现,维护和证明符合来自内部需求的安全要求,3RD党要求和国际法规和(2)以经济高效的方式管理要求,政策和安全配置。目前流程和工具的缺陷迫使这些服务提供商履行盈利能力和符合要求。本文总结了一项策略链的新方法,该方法将高级,摘要和陈述安全策略联系在另一边的一侧和低级,必要和技术安全配置设置上。本文介绍了通过状态机链接多个应用程序和模型的体系结构,以便提供支持服务提供商的工具集,以在设计时构建这种整体政策链,并在系统操作期间维护和利用它。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号