...
首页> 外文期刊>Information Technology >Utilizing architecture models for secure distributed web applications and services
【24h】

Utilizing architecture models for secure distributed web applications and services

机译:利用体系结构模型来保护分布式Web应用程序和服务的安全

获取原文
获取原文并翻译 | 示例
           

摘要

Today's Web applications are often compositions of distributed yet interconnected services that offer features and data through denned interfaces via standardized protocols. Providing a set of best practices for organizing and utilizing distributed capabilities, the service-oriented architecture design pattern largely contributed to this trend. To react on emerging customer requirements, using agile methodology for Web application development fits well in this context. While it allows promptly responding to change by adjusting the Web application architecture, security must be applied as a holistic approach throughout the entire Web application's lifecycle. There is a need for a flexible, expressive and easy-to-use way to model a Web application's architecture with a strong emphasis on security. This article discusses our work on extending the WebComposition Architecture Model towards a semantically enriched description of a Web application's architecture. For enabling systematic exploitation of such architecture descriptions, we utilize W3C's WebID identity mechanism, the WAC authorization method, and finegrained filters. We explain how WebID can be applied to allow Web services to mutually authenticate and exchange data, e. g., interface definitions and service parameters, in a controlled way.
机译:当今的Web应用程序通常是分布式但互连的服务的组合,这些服务通过标准化协议通过限定的接口提供功能和数据。通过提供一组用于组织和利用分布式功能的最佳实践,面向服务的体系结构设计模式在很大程度上推动了这一趋势。为了对新兴的客户需求做出反应,使用敏捷方法进行Web应用程序开发非常适合这种情况。尽管它可以通过调整Web应用程序体系结构来快速响应更改,但必须在整个Web应用程序的整个生命周期中将安全性作为一种整体方法来应用。需要一种灵活,易表达且易于使用的方法来对Web应用程序的体系结构进行建模,并特别强调安全性。本文讨论了我们将WebComposition体系结构模型扩展为Web应用程序体系结构的语义丰富描述的工作。为了能够系统地利用此类体系结构描述,我们利用W3C的WebID身份机制,WAC授权方法和细粒度的过滤器。我们将说明如何应用WebID来允许Web服务相互认证和交换数据,例如。例如,接口定义和服务参数以受控的方式。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号