• DocumentCode
    2396908
  • Title

    Integration of legacy client-server applications in a secure multi-tier architecture

  • Author

    Cotroneo, D. ; Mazzeo, A. ; Romano, L. ; Russo, S.

  • Author_Institution
    Universita degli Studi di Napoli "Federico II", Italy
  • fYear
    2002
  • fDate
    2002
  • Firstpage
    269
  • Lastpage
    276
  • Abstract
    Presents a CORBA-based multi-tier architecture which is capable of adding security to an existing service. We assume the legacy application is available as a compiled program consisting of a client and a server module. Under these assumptions, we show how to build a new system which re-integrates the original service and secures it. The architecture we propose is quite flexible and represents a framework which can be adopted - with minor changes - for improving the security level of a wide class of legacy systems. A system prototype has been developed and its performance evaluated. The prototype uses digital certificates which can be provided by virtually any certification authority. A fundamental advantage of the proposed approach is that the legacy server is integrated in the secure system with no changes being made to it. This minimizes the development effort, since full reuse of existing software is achieved. Furthermore, backward compatibility is preserved, since it is possible to integrate the new clients with the pre-existing applications, protecting the investment in legacy systems
  • Keywords
    certification; client-server systems; distributed object management; integrated software; security of data; software architecture; software performance evaluation; backward compatibility; challenge-response protocols; compiled program; digital certificates; legacy client-server applications integration; legacy server; legacy systems investment; minimum development effort; secure CORBA-based multi-tier architecture; security level improvement; software reuse; system prototype performance evaluation; Certification; Computer languages; Investments; Production systems; Protection; Protocols; Prototypes; Security; System testing; Virtual prototyping;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel, Distributed and Network-based Processing, 2002. Proceedings. 10th Euromicro Workshop on
  • Conference_Location
    Canary Islands
  • Print_ISBN
    0-7695-1444-8
  • Type

    conf

  • DOI
    10.1109/EMPDP.2002.994289
  • Filename
    994289