Roberto S. de O. Júnior, R. C. A. D. Silva, Marcelo Souza Santos, D. Albuquerque, H. Almeida, Danilo F. S. Santos
{"title":"An Extensible and Secure Architecture based on Microservices","authors":"Roberto S. de O. Júnior, R. C. A. D. Silva, Marcelo Souza Santos, D. Albuquerque, H. Almeida, Danilo F. S. Santos","doi":"10.1109/ICCE53296.2022.9730757","DOIUrl":null,"url":null,"abstract":"In the Internet of Things (IoT) scenario, the distributed cross-domain nature of microservices needs secure token service (STS), key management and encryption services for authentication and authorization, and secure communication protocols. Similarly, the nature of clustered containers (in which microservices are implemented) calls for secure service discovery. The availability requirement calls for: (a) resiliency techniques, such as load balancing, circuit breaking, and throttling, and (b) continuous monitoring (for the health of the service). The service mesh is the best-known approach that can facilitate the specification of these requirements at a level of abstraction such that it can be uniformly and consistently defined while also being effectively implemented without making changes to individual microservice code. The purpose of this work is to provide deployment guidance for a robust security infrastructure for supporting microservices-based applications.","PeriodicalId":350644,"journal":{"name":"2022 IEEE International Conference on Consumer Electronics (ICCE)","volume":"69 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-01-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE International Conference on Consumer Electronics (ICCE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCE53296.2022.9730757","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
In the Internet of Things (IoT) scenario, the distributed cross-domain nature of microservices needs secure token service (STS), key management and encryption services for authentication and authorization, and secure communication protocols. Similarly, the nature of clustered containers (in which microservices are implemented) calls for secure service discovery. The availability requirement calls for: (a) resiliency techniques, such as load balancing, circuit breaking, and throttling, and (b) continuous monitoring (for the health of the service). The service mesh is the best-known approach that can facilitate the specification of these requirements at a level of abstraction such that it can be uniformly and consistently defined while also being effectively implemented without making changes to individual microservice code. The purpose of this work is to provide deployment guidance for a robust security infrastructure for supporting microservices-based applications.