...
首页> 外文期刊>ACM transactions on the web >A Test-Based Security Certification Scheme for Web Services
【24h】

A Test-Based Security Certification Scheme for Web Services

机译:Web服务的基于测试的安全认证方案

获取原文
获取原文并翻译 | 示例
           

摘要

The Service-Oriented Architecture (SOA) paradigm is giving rise to a new generation of applications built by dynamically composing loosely coupled autonomous services. Clients (i.e., software agents acting on behalf of human users or service providers) implementing such complex applications typically search and integrate services on the basis of their functional requirements and of their trust in the service suppliers. A major issue in this scenario relates to the definition of an assurance technique allowing clients to select services on the basis of their nonfunctional requirements and increasing their confidence that the selected services will satisfy such requirements. In this article, we first present an assurance solution that focuses on security and supports a test-based security certification scheme for Web services. The certification scheme is driven by the security properties to be certified and relies upon a formal definition of the service model. The evidence supporting a certified property is computed using a model-based testing approach that, starting from the service model, automatically generates the test cases to be used in the service certification. We also define a set of indexes and metrics that evaluate the assurance level and the quality of the certification process. Finally, we present our evaluation toolkit and experimental results obtained applying our certification solution to a financial service implementing the Interactive Financial eXchange (IFX) standard.
机译:面向服务的体系结构(SOA)范式正在产生通过动态组合松散耦合的自治服务而构建的新一代应用程序。实施此类复杂应用程序的客户端(即代表人类用户或服务提供商的软件代理)通常会根据其功能要求和对服务提供商的信任来搜索和集成服务。这种情况下的主要问题涉及保证技术的定义,该技术允许客户根据其非功能性需求选择服务,并增强他们对所选服务将满足此类需求的信心。在本文中,我们首先提出一种保证解决方案,该解决方案侧重于安全性并支持Web服务的基于测试的安全性认证方案。认证方案由要认证的安全属性驱动,并依赖于服务模型的正式定义。使用基于模型的测试方法计算支持认证资产的证据,该方法从服务模型开始,自动生成要用于服务认证的测试用例。我们还定义了一组指标和度量,用于评估保证级别和认证过程的质量。最后,我们介绍评估工具包和将认证解决方案应用于实施Interactive Financial eXchange(IFX)标准的金融服务所获得的实验结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号