DocumentCode :
3152068
Title :
Automated Security Service Orchestration for the Identity Management in Web Service Based Systems
Author :
Warschofsky, Robert ; Menzel, Michael ; Meinel, Christoph
Author_Institution :
Hasso-Plattner-Inst., Potsdam, Germany
fYear :
2011
fDate :
4-9 July 2011
Firstpage :
596
Lastpage :
603
Abstract :
Today, there is a huge amount of security services that can be used to implement different security requirements in Web Service based systems. For example, identity management services are required for authentication and authorization whereas message logging services are necessary to achieve non-repudiation. However, the deployment and configuration of these security services usually requires expert knowledge about the systems and expert knowledge about security requirements and implementations which a person can only learn by experience. Furthermore, today´s Web Service based systems become increasingly complex. Thus, implementing security requirements is a complex and error prone task, even for experts. For this paper, we analysed several service-based implementations for identity management and their differences in the service orchestration. We present an approach to derive the needed security services, their configuration, and their connections to the functional services, based on defined security requirements for a Web Service based system. Therefore, we evaluate the UML use case model of the system and apply service security pattern derived during the analysis of the identity management implementations.
Keywords :
Unified Modeling Language; Web services; formal specification; security of data; service-oriented architecture; UML use case model; Web service based system; authentication; authorization; expert knowledge; functional service; identity management service; message logging service; security requirement; security service orchestration; service security pattern; service-oriented architecture; Authentication; Context; Service oriented architecture; System analysis and design; Unified modeling language; Identity Management; Pattern-bases Security Engineering; Security Orchestration; Service-oriented Architectures; Web Services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Web Services (ICWS), 2011 IEEE International Conference on
Conference_Location :
Washington, DC
Print_ISBN :
978-1-4577-0842-8
Electronic_ISBN :
978-0-7695-4463-2
Type :
conf
DOI :
10.1109/ICWS.2011.41
Filename :
6009442
Link To Document :
بازگشت