首页> 外文期刊>Science of Computer Programming >End-to-end information flow security for web services orchestration
【24h】

End-to-end information flow security for web services orchestration

机译:Web服务编排的端到端信息流安全性

获取原文
获取原文并翻译 | 示例

摘要

Multi-party interactions in Web Service (WS) composition are hard to managed and difficult to design and verify, especially while end-to-end information flow security (IFS) must be respected. Usually, IFS is guaranteed for a data originator and ultimate recipient WS, however inter-organizational service compositions involve partners that do not necessarily share the same level of security, especially for data they do not generate nor process themselves. In this paper, we focus on the non-interference property and we present a correct-by-construction approach to build orchestrated WSs with multi-party interactions. A key ingredient of this approach is to present the system composition at an abstract level as a component-based model where the IFS verification and the system configuration are considered at early stage. When this configuration is validated, that is, no security leak is detected, we automatically generate orchestrator components that handle IFS. Afterwards, we generate accordingly BPEL processes where the IFS constraints are enforced as security WS-policies in the BPEL description of services. We develop a set of tools that automate the approach and we validate the effectiveness of our approach with well known Web service use cases.
机译:Web服务(WS)组合中的多方交互很难管理,也难以设计和验证,尤其是在必须遵守端到端信息流安全性(IFS)的情况下。通常,为数据始发者和最终接收者WS保证IFS,但是组织间服务组合涉及的伙伴不一定共享相同级别的安全性,尤其是对于他们自己不会生成或处理的数据。在本文中,我们关注于非干扰属性,并提出了一种按构造正确的方法来构建具有多方交互的协调WS。该方法的关键要素是将系统组成抽象为基于组件的模型,其中在早期阶段考虑了IFS验证和系统配置。验证此配置后,即未检测到安全漏洞,我们将自动生成处理IFS的协调器组件。之后,我们会相应地生成BPEL流程,其中在服务的BPEL描述中将IFS约束作为安全WS策略强制实施。我们开发了一套使该方法自动化的工具,并通过众所周知的Web服务用例验证了该方法的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号