DocumentCode :
2050679
Title :
A Secure Proxy-Based Cross-Domain Communication for Web Mashups
Author :
Hsiao, Shun-Wen ; Sun, Yeali S. ; Ao, Fu-Chi ; Chen, Meng Chang
Author_Institution :
Dept. of Inf. Manage., Nat. Taiwan Univ., Taipei, Taiwan
fYear :
2011
fDate :
14-16 Sept. 2011
Firstpage :
57
Lastpage :
64
Abstract :
A web mashup is a web application that integrates content from heterogeneous sources to provide users with a more integrated and seamless browsing experience. Client-side mashups differ from server-side mashups in that the content is integrated in the browser using the client-side scripts. However, the legacy same origin policy (SOP) implemented by the browsers cannot provide a flexible client-side communication mechanism to exchange information between different sources. To address this problem, we propose a secure client-side cross-domain communication model facilitated by a trusted proxy and the HTML 5 post Message method. The proxy-based model supports fine-grained access control for elements that belong to different sources in web mashups, and the design guarantees the confidentiality, integrity, and authenticity during cross-domain communications. The proxy-based design also allows users to browse mashups without installing browser plug-ins. For mashups developers, the provided API minimizes the amount of code modification. The results of experiments demonstrate that the overhead in-curred by our proxy model is low and reasonable.
Keywords :
Internet; application program interfaces; authorisation; client-server systems; data integrity; hypermedia markup languages; online front-ends; API; HTML 5 post message method; SOP; Web mashups; authenticity; browser plug-ins; client-side communication mechanism; client-side cross-domain communication model; client-side mashups; client-side scripts; code modification; confidentiality; cross-domain communications; fine-grained access control; heterogeneous sources; information exchange; integrity; legacy same origin policy; mashups developers; proxy-based design; proxy-based model; seamless browsing experience; secure proxy-based cross-domain communication; server-side mashups; trusted proxy; Access control; Browsers; Generators; HTML; Mashups; Web pages; Web Security; access control; mashups; same origin policy;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Web Services (ECOWS), 2011 Ninth IEEE European Conference on
Conference_Location :
Lugano
Print_ISBN :
978-1-4577-1532-7
Type :
conf
DOI :
10.1109/ECOWS.2011.10
Filename :
6061077
Link To Document :
بازگشت