Secure Web Service Composition with Untrusted Broker

被引:10
|
作者
Carminati, Barbara [1 ]
Ferrari, Elena [1 ]
Ngoc Hong Tran [1 ]
机构
[1] Univ Insubria, DiSTA, Como, Italy
关键词
D O I
10.1109/ICWS.2014.31
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Composite web services are usually coordinated according to a workflow, composed by several activities, each of which carried out by a service. A way to coordinate this cooperation is orchestration, which implies that the workflow underlying the composite web service is processed by a broker hosting a workflow engine (e.g., BPEL engine). According to the orchestration paradigm, the broker coordinates the invocation of services involved in the composition by passing the needed parameters. In general, all previous proposals for the service orchestration model consider the broker as a trusted entity. As such, they never payed attention to the fact that the broker is able to access several pieces of sensitive data. We believe there is the need to protect them against improper access and usage from partner services as well as the broker. To cope with these issues, in this paper, we propose a protocol based on a selective encryption able to ensure that both the broker and service partners can access only the information needed to fulfill their activities.
引用
收藏
页码:137 / 144
页数:8
相关论文
共 50 条
  • [1] MQTLS: Toward Secure MQTT Communication with an Untrusted Broker
    Lee, Hyunwoo
    Lim, Junghwan
    Kwon, Ted Taekyoung
    2019 10TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC): ICT CONVERGENCE LEADING THE AUTONOMOUS FUTURE, 2019, : 53 - 58
  • [2] SECURE SERVICE COMPOSITION IN SENSOR WEB
    Yu, Genong
    Di, Liping
    2009 IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM, VOLS 1-5, 2009, : 3882 - 3885
  • [3] Auction-based broker for dynamic web service composition
    Ono, C
    Hattori, G
    Sugaya, F
    IC'04: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INTERNET COMPUTING, VOLS 1 AND 2, 2004, : 831 - 837
  • [4] Secure service publishing with untrusted registries
    Trabelsi, Slim
    Roudier, Yves
    SECRYPT 2007: PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2007, : 175 - 179
  • [5] Privacy-Preserving Orchestrated Web Service Composition with Untrusted Brokers
    Khabou, Imen
    Rouached, Mohsen
    Viejo, Alexandre
    Sanchez, David
    INTERNATIONAL JOURNAL OF INFORMATION TECHNOLOGY AND WEB ENGINEERING, 2018, 13 (04) : 78 - 103
  • [6] On secure framework for web services in untrusted environment
    Encheva, S
    Tumin, S
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2005: OTM 2005 WORKSHOPS, PROCEEDINGS, 2005, 3762 : 79 - 88
  • [7] A broker-based framework for QoS-aware Web service composition
    Yu, T
    Lin, KJ
    2005 IEEE International Conference on e-Technology, e-Commerce and e-Service, Proceedings, 2005, : 22 - 29
  • [8] An Authentication Broker Service for Secure and Confidential EPC
    Jokhio, Imran Ali
    Xu, Jie
    2009 XXII INTERNATIONAL SYMPOSIUM ON INFORMATION, COMMUNICATION AND AUTOMATION TECHNOLOGIES, 2009, : 249 - 256
  • [9] Information flow control to secure dynamic Web service composition
    Hutter, Dieter
    Volkamer, Melanie
    SECURITY IN PERVASIVE COMPUTING, PROCEEDINGS, 2006, 3934 : 196 - 210
  • [10] Secure composition of untrusted code: Wrappers and causality types
    Sewell, P
    Vitek, J
    13TH IEEE COMPUTER SECURITY FOUNDATIONS WORKSHOP, PROCEEDINGS, 2000, : 269 - 284