Middleware Support for Complex and Distributed Security Services in Multi-tier Web Applications

被引:0
|
作者
De Ryck, Philippe [1 ]
Desmet, Lieven [1 ]
Joosen, Wouter [1 ]
机构
[1] Katholieke Univ Leuven, IBBT DistriNet, B-3001 Louvain, Belgium
来源
关键词
middleware; multi-tier architecture; security; web application; non-repudiation; !text type='JAVA']JAVA[!/text;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The security requirements of complex multi-tier web applications have shifted from simple localized needs, such as authentication or authorization, to physically distributed but actually aggregated services, such as end-to-end data protection, non-repudiation or patient consent management. Currently, there is no support for integrating complex security services in web architectures, nor are approaches from other architectural models easily portable. In this paper we present the architecture of a security middleware, aimed at providing a reusable solution bringing support for complex security requirements into the application architecture, while addressing typical web architecture challenges, such as the tiered model or the lack of sophisticated client-side logic. We both evaluate the security of the middleware and present a case study and prototype implementation, which show how the complexities of a web architecture can be dealt with while limiting the integration effort.
引用
收藏
页码:114 / 127
页数:14
相关论文
共 50 条
  • [1] LWeb: Information Flow Security or Multi-tier Web Applications
    Parker, James
    Vazou, Niki
    Hicks, Michael
    [J]. PROCEEDINGS OF THE ACM ON PROGRAMMING LANGUAGES-PACMPL, 2019, 3 (POPL):
  • [2] Research on Multi-tier Distributed Systems Based on AOP and Web Services
    Zhang, Jingjun
    Meng, Fanxin
    Liu, Guangyuan
    [J]. PROCEEDINGS OF THE FIRST INTERNATIONAL WORKSHOP ON EDUCATION TECHNOLOGY AND COMPUTER SCIENCE, VOL II, 2009, : 203 - 207
  • [3] Maintaining multi-tier web applications
    Zheng, Xiaoyu
    Chen, Mei-Hwa
    [J]. 2007 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE, 2007, : 304 - 313
  • [4] A Survey of Resource Management in Multi-Tier Web Applications
    Huang, Dong
    He, Bingsheng
    Miao, Chunyan
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2014, 16 (03): : 1574 - 1590
  • [5] A SURVEY OF QUALITY OF SERVICE IN MULTI-TIER WEB APPLICATIONS
    Ghetas, Mohamed
    Yong, Chan Huah
    Sumari, Putra
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2016, 10 (01): : 238 - 256
  • [6] Instant Multi-Tier Web Applications without Tears
    Shroff, Gautam
    Agarwal, Puneet
    Devanbu, Premkumar
    [J]. ISEC 2009 - PROCEEDINGS OF THE 2ND INDIA SOFTWARE ENGINEERING CONFERENCE, 2009, : 3 - 12
  • [7] An Execution Tracing Tool for Multi-tier Web Applications
    Xu, Jian
    Zhang, Hong
    Li, QianMu
    [J]. ADVANCED RESEARCH ON COMPUTER SCIENCE AND INFORMATION ENGINEERING, 2011, 153 : 244 - 250
  • [8] Modeling autonomic recovery in web services with multi-tier reboots
    Zhang, Rui
    [J]. 2007 IEEE International Conference on Web Services, Proceedings, 2007, : 1222 - 1223
  • [9] Review of middleware components in multi-tier structures
    Chen, QY
    Sharma, V
    Wang, J
    [J]. ISSUES AND TRENDS OF INFORMATION TECHNOLOGY MANAGEMENT IN CONTEMPORARY ORGANIZATIONS, VOLS 1 AND 2, 2002, : 123 - 127
  • [10] Stochastic Model for QoS Assessment in Multi-tier Web Services
    Czekster, Ricardo M.
    Fernandes, Paulo
    Sales, Afonso
    Webber, Thais
    Zorzo, Avelino F.
    [J]. ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2011, 275 : 53 - 72