• DocumentCode
    3127688
  • Title

    Generic Security Policy Transformation Framework for WS-Security

  • Author

    Satoh, Fumiko ; Yamaguchi, Yumi

  • Author_Institution
    IBM Res., Yamato
  • fYear
    2007
  • fDate
    9-13 July 2007
  • Firstpage
    513
  • Lastpage
    520
  • Abstract
    Model-driven security is a framework to configure WS-security easily. It generates a security policy written in WS-security policy to be transformed into platform-specific configuration files. Since the WS-security policy specification is quite complicated, it is difficult to directly map between a security policy and a configuration. We propose a generic security policy transformation framework using an intermediate model. The intermediate model structure is designed based on the WS-security message structure, because both a security policy and the configuration files correspond to one WS-security message, even though the WS-security policy is flexible in specifying security requirements. Our contributions are simpler transformation rules compared to direct mapping, the support for various platforms, and more flexible updates if the WS-security policy specification changes. We demonstrate the transformation using the intermediate model for WebSphere application server 6.0.
  • Keywords
    Web services; message passing; security of data; specification languages; WS-security message structure; WS-security policy specification language; Web service security; WebSphere application server 6.0; model-driven security framework; platform-specific configuration file; security policy transformation framework; Cryptography; File servers; Information security; Laboratories; Runtime; Web services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Web Services, 2007. ICWS 2007. IEEE International Conference on
  • Conference_Location
    Salt Lake City, UT
  • Print_ISBN
    0-7695-2924-0
  • Type

    conf

  • DOI
    10.1109/ICWS.2007.92
  • Filename
    4279638