首页> 外文期刊>Service Oriented Computing and Applications >PBA4WSSP: a policy-based architecture for web services security processing
【24h】

PBA4WSSP: a policy-based architecture for web services security processing

机译:PBA4WSSP:用于Web服务安全处理的基于策略的体系结构

获取原文
获取原文并翻译 | 示例
           

摘要

Due to the dynamic, heterogeneous and interorganizational nature, different web services and different ports or operations in the same service, even the same services at different times may have their different security requirements because of their different security domains and different business backgrounds. How to design a flexible, fine-grained and comprehensive architecture for web services security processing has become a matter of great urgency. However, no ideal solutions have been worked out for these problems. As a result of our study, we have presented in this paper a policy-based architecture termed policy-based architecture for web services security processing (PBA4WSSP) to meet the dynamic, complete and fine-grained security requirements. In PBA4WSSP, the processing of all security problems is based on security policy in service stage to support flexibly security configuration. Moreover, we have designed a service policy model to describe the fine-grained security requirements. And the conversion method between security policy model and security policy expression has also been described. In addition, a staged complete security processing architecture is provided to reduce the dependency among protocol implementations. Furthermore, with PBA4WSSP, a web service security module has been designed and implemented as well. Eventually, the performance evaluation results amply demonstrate that our system is flexible and usable.
机译:由于动态,异构和组织间的特性,不同的Web服务以及同一服务中的不同端口或操作,即使是相同时间的相同服务,由于其不同的安全域和不同的业务背景也可能具有不同的安全要求。如何为Web服务安全处理设计一个灵活,细粒度和全面的体系结构已成为当务之急。但是,还没有针对这些问题的理想解决方案。作为我们研究的结果,我们在本文中提出了一种基于策略的体系结构,称为Web服务安全处理的基于策略的体系结构(PBA4WSSP),可以满足动态,完整和细粒度的安全性要求。在PBA4WSSP中,所有安全问题的处理均基于服务阶段的安全策略,以灵活支持安全配置。此外,我们设计了一个服务策略模型来描述细粒度的安全要求。并描述了安全策略模型与安全策略表达之间的转换方法。另外,提供了分阶段的完整安全处理体系结构,以减少协议实现之间的依赖性。此外,借助PBA4WSSP,还已经设计和实现了Web服务安全模块。最终,性能评估结果充分证明了我们的系统是灵活且可用的。

著录项

  • 来源
    《Service Oriented Computing and Applications》 |2014年第1期|55-72|共18页
  • 作者单位

    1.TP-470Key Laboratory of Software Development Environment School of Computer Science and Engineering Beihang University Beijing China;

    1.TP-470Key Laboratory of Software Development Environment School of Computer Science and Engineering Beihang University Beijing China;

    1.TP-470Key Laboratory of Software Development Environment School of Computer Science and Engineering Beihang University Beijing China;

    1.TP-470Key Laboratory of Software Development Environment School of Computer Science and Engineering Beihang University Beijing China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Web services; Security; Security policy; PBA4WSSP;

    机译:Web服务;安全性;安全性策略;PBA4WSSP;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号