Implementing conflict of interest assertions for Web services matchmaking process

P. Hung, Guang-Sha Qiu
{"title":"Implementing conflict of interest assertions for Web services matchmaking process","authors":"P. Hung, Guang-Sha Qiu","doi":"10.1109/COEC.2003.1210273","DOIUrl":null,"url":null,"abstract":"A Web service is defined as an autonomous unit of application logic that provides either some business functionality or information to other applications through an Internet connection. Web services are based on a set of XML standards such as simple object access protocol (SOAP), universal description, discovery and integration (UDDI), and Web services description language (WSDL). The benefits of adopting Web services over traditional business-to-business applications include faster time to production, convergence of disparate business functionalities, a significant reduction in total cost of development, and easy to deploy business applications for trading partners. However, Web services architectures are built on an insecure, unmonitored, and shared environment, which is open to events such as security threats. Security concerns are the major barrier that prevents many business organizations from implementing or employing Web services. This paper discusses one of the classical security policies that deal with conflict of interest - the Chinese wall security policy. The paper then extends this concept into specifying and implementing conflict of interest assertions in the newly developed WS-Policy. WS-Policy is an XML representation that provides a grammar for expressing Web services policies, to allow service locators to have a common interpretation of security requirements in the matchmaking process. Further, this paper also describes a prototype Web service called \"CIRService\" for supporting conflict of interest assertions in matchmaking process. The paper will conclude with identification of further research into the area of identifying hierarchical structure and relationship among Web services, to be considered in the matchmaking process.","PeriodicalId":375124,"journal":{"name":"EEE International Conference on E-Commerce, 2003. CEC 2003.","volume":"48 9-10","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2003-06-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"EEE International Conference on E-Commerce, 2003. CEC 2003.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/COEC.2003.1210273","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 8

Abstract

A Web service is defined as an autonomous unit of application logic that provides either some business functionality or information to other applications through an Internet connection. Web services are based on a set of XML standards such as simple object access protocol (SOAP), universal description, discovery and integration (UDDI), and Web services description language (WSDL). The benefits of adopting Web services over traditional business-to-business applications include faster time to production, convergence of disparate business functionalities, a significant reduction in total cost of development, and easy to deploy business applications for trading partners. However, Web services architectures are built on an insecure, unmonitored, and shared environment, which is open to events such as security threats. Security concerns are the major barrier that prevents many business organizations from implementing or employing Web services. This paper discusses one of the classical security policies that deal with conflict of interest - the Chinese wall security policy. The paper then extends this concept into specifying and implementing conflict of interest assertions in the newly developed WS-Policy. WS-Policy is an XML representation that provides a grammar for expressing Web services policies, to allow service locators to have a common interpretation of security requirements in the matchmaking process. Further, this paper also describes a prototype Web service called "CIRService" for supporting conflict of interest assertions in matchmaking process. The paper will conclude with identification of further research into the area of identifying hierarchical structure and relationship among Web services, to be considered in the matchmaking process.
为Web服务匹配过程实现利益冲突断言
Web服务被定义为应用程序逻辑的自治单元,它通过Internet连接向其他应用程序提供某些业务功能或信息。Web服务基于一组XML标准,如简单对象访问协议(SOAP)、通用描述、发现和集成(UDDI)以及Web服务描述语言(WSDL)。与传统的企业对企业应用程序相比,采用Web服务的好处包括更快的生产时间、不同业务功能的聚合、开发总成本的显著降低,以及为贸易伙伴轻松部署业务应用程序。但是,Web服务体系结构构建在不安全、不受监视和共享的环境上,这种环境对安全威胁等事件是开放的。安全问题是阻碍许多业务组织实现或使用Web服务的主要障碍。本文讨论了处理利益冲突的经典安全策略之一——中国墙安全策略。然后,本文将这一概念扩展到在新开发的WS-Policy中指定和实现利益冲突断言。WS-Policy是一种XML表示,它提供了用于表示Web服务策略的语法,从而允许服务定位器在匹配过程中对安全需求有一个共同的解释。此外,本文还描述了一个名为“CIRService”的原型Web服务,用于支持撮合过程中的利益冲突断言。最后,本文将进一步研究识别Web服务之间的层次结构和关系,这将在匹配过程中考虑。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信