Title :
Towards Systematic Engineering of Service-Oriented Access Control in Federated Environments
Author :
Hollrigl, T. ; Schell, F. ; Suelmann, S. ; Hartenstein, H.
Author_Institution :
Inst. of Telematics, Univ. of Karlsruhe, Karlsruhe
Abstract :
The success of service-oriented architectures (SOAs) and the Web Service technology in fulfilling the business´s needs for inter-enterprise processes led to new challenges for security management in federated environments. Because of the predominant aspect of loose coupling in a SOA the issue of where to locate the processes of authentication and authorization, forming together the access control, a vital part of security management, has to be addressed during the design of access control systems. In the area of tension between local, service-oriented, and federated approaches for access control architectures we identify several essential dimensions, e.g. scalability and maintenance, for evaluating access control architectures. Due to the challenges of quantifying the metrics we propose a ranking system as it is widely used in risk assessment. We examine existing access control architectures and evaluate the different approaches based on our evaluation dimensions. The results of the performed evaluation will guide the design decisions of an organization fulfilling its security requirements in requirements engineering and software design. A case study illustrates how the evaluation criteria serve as a pattern to establish an organization´s access control to secure Web Services.
Keywords :
Web services; authorisation; business data processing; software architecture; software maintenance; Web Service technology; authentication process; authorization process; inter-enterprise processes; risk assessment; security management; service-oriented access control; service-oriented architectures; systematic engineering; Access control; Authentication; Authorization; Environmental management; Scalability; Security; Service oriented architecture; Systems engineering and theory; Technology management; Web services; Access Control; Federation; Service-Oriented Architecture;
Conference_Titel :
Congress on Services Part II, 2008. SERVICES-2. IEEE
Conference_Location :
Beijing
Print_ISBN :
978-0-7695-3313-1
Electronic_ISBN :
978-0-7695-3313-1
DOI :
10.1109/SERVICES-2.2008.24