Service Oriented Security Architecture

被引:0
|
作者
Opincaru, Cristian [1 ]
Gheorghe, Gabriela [2 ]
机构
[1] Univ German Armed Forces, Werner Heisenberg Weg 39, D-85577 Neubiberg, Germany
[2] Univ Trento, ICT Int Doctorate Sch, I-38100 Povo, Italy
关键词
D O I
暂无
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
As Service Oriented Architectures (SOA) and Web services are becoming widely deployed, the issue of security is far from being solved. In an attempt to address this issue, the industry proposed several extensions to the SOAP protocol that currently reached different levels of standardization. However, no architectural guidelines have yet been proposed. In this paper we first outline the security challenges and the specifications that address these challenges and then present our concept the Service Oriented Security Architecture-SOSA. We argue that the different security functions (authentication, authorization, audit, etc.) should be realized as different stand-alone Web services These security services can then be chained together by means of Enterprise Application Integration (EAI) techniques such as message routing on Enterprise Services Buses (ESB). Next, we will present a prototypical implementation of this framework and describe our experiences so far. We show that by distributing the security functions, a more flexible architecture can be designed that would lower the costs associated with implementation, administration and maintenance.
引用
收藏
页码:39 / 48
页数:10
相关论文
共 50 条
  • [1] Security Type Comparison In Service Oriented Architecture Security
    Yesiltepe, Mirsat
    Bozkurt, Omer Ozgur
    [J]. WORLD CONFERENCE ON TECHNOLOGY, INNOVATION AND ENTREPRENEURSHIP, 2015, : 1833 - 1839
  • [2] Service Level Security Enhacement for Service Oriented Architecture
    Shashwat, Anurag
    Kumar, Deepak
    Chanana, Lovneesh
    [J]. 2018 INTERNATIONAL CONFERENCE ON COMPUTING, POWER AND COMMUNICATION TECHNOLOGIES (GUCON), 2018, : 79 - 83
  • [3] Trading off security in a service oriented architecture
    Swart, G
    Aziz, B
    Foley, SN
    Herbert, J
    [J]. DATA AND APPLICATIONS SECURITY XIX, PROCEEDINGS, 2005, 3654 : 295 - 309
  • [4] Software Security in the Model for Service Oriented Architecture Quality
    Kolaczek, Grzegorz
    Wasilewski, Adam
    [J]. PARALLEL PROCESSING AND APPLIED MATHEMATICS, PT I, 2010, 6067 : 226 - 235
  • [5] An End to End Security Framework for Service Oriented Architecture
    Shashwat, Anurag
    Kumar, Deepak
    Chanana, Lovneesh
    [J]. 2017 INTERNATIONAL CONFERENCE ON INFOCOM TECHNOLOGIES AND UNMANNED SYSTEMS (TRENDS AND FUTURE DIRECTIONS) (ICTUS), 2017, : 475 - 480
  • [6] SEROSA: SERvice Oriented Security Architecture for Vehicular Communications
    Gisdakis, Stylianos
    Lagana, Marcello
    Giannetsos, Thanassis
    Papadimitratos, Panos
    [J]. 2013 IEEE VEHICULAR NETWORKING CONFERENCE (VNC), 2013, : 111 - 118
  • [7] The Security of Collaborative Commerce Based on Service Oriented Architecture
    Gui, Wei-Xia
    Zhang, Xiao-Ping
    [J]. ICIC 2009: SECOND INTERNATIONAL CONFERENCE ON INFORMATION AND COMPUTING SCIENCE, VOL 1, PROCEEDINGS, 2009, : 301 - 304
  • [8] Integration of a Security Product in Service-oriented Architecture
    Dikanski, Aleksander
    Emig, Christian
    Abeck, Sebastian
    [J]. 2009 THIRD INTERNATIONAL CONFERENCE ON EMERGING SECURITY INFORMATION, SYSTEMS, AND TECHNOLOGIES, 2009, : 1 - 7
  • [9] Security requirements for a semantic service-oriented architecture
    Duerbeck, Stefan
    Schillinger, Rolf
    Kolter, Jan
    [J]. ARES 2007: SECOND INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, PROCEEDINGS, 2007, : 366 - +
  • [10] Developing a Security Robot in Service-Oriented Architecture
    Chen, Yinong
    Abhyankar, S.
    Xu, L.
    Tsai, W. T.
    Garcia-Acosta, Marcos
    [J]. 12TH IEEE INTERNATIONAL WORKSHOP ON FUTURE TRENDS OF DISTRIBUTED COMPUTING SYSTEMS, PROCEEDINGS, 2008, : 106 - +