首页> 外文学位 >Secure service composition with information flow control.
【24h】

Secure service composition with information flow control.

机译:通过信息流控制来保护服务组合。

获取原文
获取原文并翻译 | 示例

摘要

Service-Oriented Architecture (SOA) is the current paradigm to achieve global system integration and collaboration. Although SOA has many benefits, security is still a major concern. Access control is one of the major issues in secure SOA. It is necessary to develop suitable access control models to secure individual web services. Also, when multiple services hosted by different providers are composed together to realize certain business logic, it is desirable to ensure the secure interactions between the involved entities. In this dissertation, we focus on three major access control issues in service composition: (1) Information flow control, which controls the propagation of sensitive information in composite services, (2) Integration of action-level access control and fine-grained data resource level access control to secure web services, and (3) Composition-time access control validation to minimize the execution-time failure rate of the composed composite services.;In this dissertation, we take a close look at these three issues and provide a comprehensive set of solutions to the secure service composition in multi-domain web service environment. First, we have developed a fine-grained information flow control model (Chapter 4) and introduced the novel concept of transformation factor to model the computation and "transformation" effect of intermediate services. Our approach can significantly simplify the information flow control policies and improve the access control validation performance. Second, we have developed a fine-grained data resource level information flow control model (Chapter 7) based on the data flow analysis and tracking techniques. This model is capable of securing the flow of data that are dynamically generated in composite services. Third, we develop protocols to achieve composition-time access control considering both mediator-based (Chapter 5) and fully decentralized composition architectures (Chapter 6). Our protocols are highly efficient and can greatly enhance the performance in composing and executing composite services with proper information flow control constraints.
机译:面向服务的体系结构(SOA)是实现全局系统集成和协作的当前范例。尽管SOA有很多好处,但是安全性仍然是主要关注的问题。访问控制是安全SOA中的主要问题之一。有必要开发合适的访问控制模型以保护单个Web服务。而且,当将由不同提供者托管的多个服务组合在一起以实现某些业务逻辑时,希望确保所涉及实体之间的安全交互。本文主要研究服务组合中的三个主要访问控制问题:(1)信息流控制,控制组合服务中敏感信息的传播;(2)动作级访问控制和细粒度数据资源的集成级别的访问控制以确保Web服务的安全;以及(3)组合时访问控制验证,以最大程度地降低组合的组合服务的执行时间失败率。本文对这三个问题进行了仔细研究,并提供了全面的信息。多域Web服务环境中的安全服务组合解决方案集。首先,我们开发了一种细粒度的信息流控制模型(第4章),并引入了转换因子的新概念来对中间服务的计算和“转换”效果进行建模。我们的方法可以大大简化信息流控制策略并提高访问控制验证性能。其次,我们基于数据流分析和跟踪技术开发了细粒度的数据资源级信息流控制模型(第7章)。该模型能够保护组合服务中动态生成的数据流。第三,我们考虑基于介体的(第5章)和完全分散的合成体系结构(第6章),开发协议以实现合成时间访问控制。我们的协议非常高效,并且可以在适当的信息流控制约束下极大地提高组合和执行复合服务的性能。

著录项

  • 作者

    She, Wei.;

  • 作者单位

    The University of Texas at Dallas.;

  • 授予单位 The University of Texas at Dallas.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2011
  • 页码 143 p.
  • 总页数 143
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 康复医学;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号