首页> 外文期刊>Peer-to-peer networking and applications >Context-aware trust negotiation in peer-to-peer service collaborations - Springer
【24h】

Context-aware trust negotiation in peer-to-peer service collaborations - Springer

机译:对等服务协作中的上下文感知信任协商-Springer

获取原文
获取原文并翻译 | 示例

摘要

Service-oriented architecture (SOA) and Software as a Service (SaaS) are the latest hot topics to software manufacturing and delivering, and attempt to provide a dynamic cross-organisational business integration solution. In a dynamic cross-organisational collaboration environment, services involved in a business process are generally provided by different organisations, and lack supports of common security mechanisms and centralized management middleware. On such occasions, services may have to achieve middleware functionalities and achieve business objectives in a pure peer-to-peer fashion. As the participating services involved in a business process may be selected and combined at run time, a participating service may have to collaborate with multiple participating services which it has no pre-existing knowledge in prior. This introduces some new challenges to traditional trust management mechanisms. Automated Trust Negotiation (ATN) is a practical approach which helps to generate mutual trust relationship for collaborating principals which may have no pre-existing knowledge about each other without in a peer-to-peer way. Because credentials often contain sensitive attributes, ATN defines an iterative and bilateral negotiation process for credentials exchange and specifies security policies that regulate the disclosure of sensitive credentials. Credentials disclosure in the iterative process may follow different orders and combinations, each of which forms a credential chain. It is practically desirable to identify the optimal credential chain that satisfies certain objectives such as minimum release of sensitive information and minimum performance penalty. In this paper we present a heuristic and context-aware algorithm for identifying the optimal chain that uses context-related knowledge to minimize 1) the release of sensitive information including both credentials and policies and 2) the cost of credentials retrieving. Moreover, our solution offers a hierarchical method for protecting sensitive policies and provides a risk-based strategy for handling credential circular dependency. We have implemented the ATN mechanisms based on our algorithm and incorporated them into the CROWN Grid middleware. Experimental results demonstrate their performance-related advantages over other existing solutions.
机译:面向服务的体系结构(SOA)和软件即服务(SaaS)是软件制造和交付的最新热点,并试图提供动态的跨组织业务集成解决方案。在动态的跨组织协作环境中,业务流程中涉及的服务通常由不同的组织提供,并且缺乏对通用安全机制和集中管理中间件的支持。在这种情况下,服务可能必须以纯对等方式实现中间件功能并实现业务目标。由于业务流程中涉及的参与服务可以在运行时进行选择和组合,因此参与服务可能必须与多个参与服务进行协作,而这些参与服务之前并没有预先存在的知识。这给传统的信任管理机制带来了一些新的挑战。自动信任协商(ATN)是一种实用的方法,它可以帮助协作主体之间建立互信关系,而如果没有对等方式,彼此之间可能就不存在彼此之间的知识。由于凭据通常包含敏感属性,因此ATN为凭据交换定义了迭代的双边协商过程,并指定了用于管理敏感凭据公开的安全策略。迭代过程中的凭证公开可以遵循不同的顺序和组合,每个顺序和组合都形成凭证链。实际需要确定满足某些目标(例如,敏感信息的最小发布和最小性能损失)的最佳凭据链。在本文中,我们提出了一种启发式和上下文感知算法,用于识别最佳链,该算法使用与上下文相关的知识来最小化1)释放包括凭据和策略在内的敏感信息,以及2)凭据获取的成本。此外,我们的解决方案提供了一种用于保护敏感策略的分层方法,并提供了一种基于风险的策略来处理凭证循环依赖性。我们已经基于算法实现了ATN机制,并将其合并到CROWN Grid中间件中。实验结果证明了它们与其他现有解决方案相比在性能方面的优势。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号