• DocumentCode
    1732270
  • Title

    Towards Systematic Engineering of Service-Oriented Access Control in Federated Environments

  • Author

    Hollrigl, T. ; Schell, F. ; Suelmann, S. ; Hartenstein, H.

  • Author_Institution
    Inst. of Telematics, Univ. of Karlsruhe, Karlsruhe
  • fYear
    2008
  • Firstpage
    104
  • Lastpage
    111
  • Abstract
    The success of service-oriented architectures (SOAs) and the Web Service technology in fulfilling the business´s needs for inter-enterprise processes led to new challenges for security management in federated environments. Because of the predominant aspect of loose coupling in a SOA the issue of where to locate the processes of authentication and authorization, forming together the access control, a vital part of security management, has to be addressed during the design of access control systems. In the area of tension between local, service-oriented, and federated approaches for access control architectures we identify several essential dimensions, e.g. scalability and maintenance, for evaluating access control architectures. Due to the challenges of quantifying the metrics we propose a ranking system as it is widely used in risk assessment. We examine existing access control architectures and evaluate the different approaches based on our evaluation dimensions. The results of the performed evaluation will guide the design decisions of an organization fulfilling its security requirements in requirements engineering and software design. A case study illustrates how the evaluation criteria serve as a pattern to establish an organization´s access control to secure Web Services.
  • Keywords
    Web services; authorisation; business data processing; software architecture; software maintenance; Web Service technology; authentication process; authorization process; inter-enterprise processes; risk assessment; security management; service-oriented access control; service-oriented architectures; systematic engineering; Access control; Authentication; Authorization; Environmental management; Scalability; Security; Service oriented architecture; Systems engineering and theory; Technology management; Web services; Access Control; Federation; Service-Oriented Architecture;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Congress on Services Part II, 2008. SERVICES-2. IEEE
  • Conference_Location
    Beijing
  • Print_ISBN
    978-0-7695-3313-1
  • Electronic_ISBN
    978-0-7695-3313-1
  • Type

    conf

  • DOI
    10.1109/SERVICES-2.2008.24
  • Filename
    4700506