首页> 外文OA文献 >Context-aware and model-driven approach for embedding and verifying security into composed web services. (c2013)
【2h】

Context-aware and model-driven approach for embedding and verifying security into composed web services. (c2013)

机译:上下文感知和模型驱动的方法,用于将安全性嵌入和验证到组合的Web服务中。 (c2013)

摘要

Today's process-oriented composition languages such as BPEL (Business Process Execution Language) offer a high level of abstraction and sophistication to Web services composition. However, such languages suffer serious drawbacks with respect to security, modularity and adaptability. Particularly, they lack the security features needed in distributed computationalenvironments like Web services composition. In addition, they do not provide means for an explicit and well-modularized specification of cross-cutting concerns. They also do not support the dynamic adaptation with the environmental execution changes. In this thesis, weadvocate new approach that provides systematic and model-driven security specification at the Web services composition level, in addition to dynamic integration in a seamless fashion. It is based on an extension of the BPEL meta-model with new aspect-oriented constructs for designing and building modularized, secure, conflict-free and highly adaptable Web servicescomposition within BPEL processes. Moreover, we extend our approach by adopting security licenses in BPEL and provide process level license verification that replaces the monopolization of such validation at the Web services side. Furthermore, we introduce two different real-life case studies along with performance analysis and experimental results to demonstrate the usefulness of our proposition. Finally, we carry out a formal verificationmechanism to ensure that the integration of the new security aspects does not affect the original behavior of the Web services business process, which remains deadlock and conflictfree.
机译:诸如BPEL(业务流程执行语言)之类的当今面向流程的组合语言为Web服务组合提供了高度的抽象和复杂性。但是,这些语言在安全性,模块化和适应性方面遭受严重的缺点。特别是,它们缺乏分布式计算环境(如Web服务组合)所需的安全性功能。此外,它们没有提供明确且模块化良好的跨领域关注点的手段。它们也不支持随着环境执行变化而进行的动态适应。在本文中,我们提倡一种新方法,该方法除了以无缝方式进行动态集成外,还可以在Web服务组合级别提供系统的和模型驱动的安全性规范。它基于BPEL元模型的扩展,具有新的面向方面的构造,用于在BPEL流程中设计和构建模块化,安全,无冲突和高度适应性的Web服务组合。此外,我们通过在BPEL中采用安全许可来扩展我们的方法,并提供流程级别的许可验证,以取代Web服务端这种验证的垄断。此外,我们介绍了两个不同的实际案例研究以及性能分析和实验结果,以证明我们的命题的有用性。最后,我们执行正式的验证机制以确保新安全性方面的集成不会影响Web服务业务流程的原始行为,而该行为仍然处于死锁和无冲突状态。

著录项

  • 作者

    Tout Hanine Ahmad;

  • 作者单位
  • 年度 2013
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号