• DocumentCode
    1309379
  • Title

    Security Policy Composition for Composite Web Services

  • Author

    Satoh, Fumiko ; Tokuda, Takehiro

  • Author_Institution
    IBM Res. - Tokyo, Yamato, Japan
  • Volume
    4
  • Issue
    4
  • fYear
    2011
  • Firstpage
    314
  • Lastpage
    327
  • Abstract
    An application based on the Service-Oriented Architecture (SOA) consists of an assembly of services, which is referred to as a composite service. A composite service can be implemented from other composite services, and hence, the application could have a recursive structure. Securing an SOA application is an important nonfunctional requirement. However, specifying a security policy for a composite service is not easy because the policy should be consistent with the policies of the external services invoked in the composite process. Therefore, this paper proposes a security policy composition mechanism that uses the existing policies of the external services. Our contribution is defining the process-independent policy composition rules and providing a method for semiautomatically creating a security policy of the composite service. Our method supports two approaches of policy composition: top-down and bottom-up. Our study makes it possible to verify the consistency of the policies without increasing a developer´s workload, even if the composite service has a recursive structure.
  • Keywords
    Web services; security of data; service-oriented architecture; composite Web services; process independent policy composition rules; recursive structure; security policy composition; service oriented architecture; Computer architecture; Decision support systems; Quality of services; Web services; Composite web services; quality of service.;
  • fLanguage
    English
  • Journal_Title
    Services Computing, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1939-1374
  • Type

    jour

  • DOI
    10.1109/TSC.2010.40
  • Filename
    5560635