...
首页> 外文期刊>Concurrency and Computation >Refactoring service-based systems: how to avoid trusting a workflow service
【24h】

Refactoring service-based systems: how to avoid trusting a workflow service

机译:重构基于服务的系统:如何避免信任工作流服务

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Grid systems span multiple organizations, so their workflow processes have security requirements, such as restricting access to data or ensuring that process constraints are observed. These requirements are often managed by the workflow component, because of the close association between this sub-system and the processes it enacts. However, high-quality security mechanisms and complex functionality are difficult to combine, so designers and users of workflow systems are faced with a tradeoff between security and functionality, which is unlikely to provide confidence in the security implementation. This paper resolves that tension by showing that process security can be enforced outside the workflow component. Separating security and process functionality in this way improves the quality of security protection, because it is implemented by standard system mechanisms; it also allows the workflow component to be deployed as a standard service, rather than a privileged system component. To make this change of design philosophy accessible outside the security community it is documented as a collection of refactorings, which include problem templates that identify suspect design practice, and target patterns that provide solutions. Worked examples show that these patterns can be used in practice to implement practical applications, with both traditional workflow security concerns, and Grid requirements.
机译:网格系统跨越多个组织,因此其工作流程过程具有安全性要求,例如限制对数据的访问或确保遵守过程约束。这些要求通常由工作流组件管理,因为该子系统与其执行的流程之间存在紧密的联系。但是,高质量的安全机制和复杂的功能很难结合在一起,因此工作流系统的设计人员和用户都面临安全性和功能性之间的折衷,这不太可能使人们对安全性实现方式充满信心。本文通过显示可以在工作流组件之外实施流程安全性来解决这种紧张关系。通过这种方式将安全性和流程功能分开,可以提高安全保护的质量,因为它是通过标准系统机制实现的;它还允许将工作流组件部署为标准服务,而不是特权系统组件。为了使这种更改设计理念的方法在安全性社区之外可以访问,它记录为重构的集合,其中包括识别可疑设计实践的问题模板和提供解决方案的目标模式。工作示例表明,这些模式可以在实践中用于实现实际应用,同时兼顾传统的工作流安全性和网格要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号