• DocumentCode
    3429751
  • Title

    Effective and efficient implementation of an information flow control protocol for service composition

  • Author

    She, Wei ; Yen, I-Ling ; Thuraisingham, Bhavani ; Bertino, Elisa

  • Author_Institution
    Univ. of Texas at Dallas, Dallas, TX, USA
  • fYear
    2009
  • fDate
    14-15 Jan. 2009
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Due to the potential of composing Web services from multiple domains under diverse security administrations, ensuring the security in service composition can be a very challenging task. A major problem is the potential of information leakage between the interacting services. Most existing Web service security models consider the access to a single Web service and do not consider the control of such information flows. In our previous work, we proposed a novel access control model, SCIFC, that empowers the services to effectively control the flow of their sensitive information. In this paper, we consider additional mechanisms to further improve the efficiency and effectiveness of the SCIFC protocols, including a carry-along policy propagation mechanism to minimize the message sizes for policy exchanges and a transformation factor analysis scheme based on symbolic execution to assist with transformation factor assignments. Based on these enhancements, we implement the SCIFC protocol and study its performance. We develop an extensive Web service simulation framework to simulate a diverse range of Web services. The performance study of the SCIFC protocol is conducted on top of this simulation framework. Finally, we develop a case study system to validate the feasibility and effectiveness of the SCIFC protocols.
  • Keywords
    Web services; authorisation; protocols; software architecture; SCIFC protocols; Web service composition; Web service security models; access control model; carry-along policy propagation mechanism; information flow control protocol; information leakage; service-oriented architecture; transformation factor analysis scheme; transformation factor assignments; Protocols;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Service-Oriented Computing and Applications (SOCA), 2009 IEEE International Conference on
  • Conference_Location
    Taipei
  • Print_ISBN
    978-1-4244-5300-9
  • Type

    conf

  • DOI
    10.1109/SOCA.2009.5410468
  • Filename
    5410468