DocumentCode :
2099072
Title :
Bringing Common Criteria Certification to Web Services
Author :
Kaluvuri, Samuel Paul ; Bezzi, Michele ; Roudier, Yves
Author_Institution :
Appl. Res. Security&Trust, SAP Labs. France, France
fYear :
2013
fDate :
June 28 2013-July 3 2013
Firstpage :
98
Lastpage :
102
Abstract :
Solutions based on service-oriented architecture are gaining popularity. However a wider adoption, especially for business critical functions, is hampered by the trust deficit that exists between consumers and providers, as consumers are shielded from the service architectures and the operation of the service itself. Security certification can be used as a means to bridge this trust deficit. Common Criteria for Information Technology Evaluation (CC) is a widely recognized and used security certification scheme. However, the CC scheme was tailored to provide assurance for traditional software provisioning models and hence cannot be applied to SOA solutions as is. In this paper, we present the limitations of the CC scheme when applied in SOA, the challenges that must be overcome for its adoption and possible directions through which some of those challenges can be met. In particular, we point out that CC scheme should be extended to allow for dynamic evaluation of deployed systems (which includes the operational environment) and for handling assurance of composite services.
Keywords :
Web services; certification; security of data; service-oriented architecture; trusted computing; SOA; Web services; business critical functions; common criteria certification; common criteria for information technology evaluation; composite service assurance handling; deployed system dynamic evaluation; operational environment; security certification; service-oriented architecture; software provisioning model; trust deficit; Monitoring; Natural languages; Runtime; Security; Service-oriented architecture; Security Assurance; Security Ceritifcation; Web Services; Common Criteria;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Services (SERVICES), 2013 IEEE Ninth World Congress on
Conference_Location :
Santa Clara, CA
Print_ISBN :
978-0-7695-5024-4
Type :
conf
DOI :
10.1109/SERVICES.2013.17
Filename :
6655681
Link To Document :
بازگشت