An Extensible and Secure Architecture based on Microservices

Roberto S. de O. Júnior, R. C. A. D. Silva, Marcelo Souza Santos, D. Albuquerque, H. Almeida, Danilo F. S. Santos
{"title":"An Extensible and Secure Architecture based on Microservices","authors":"Roberto S. de O. Júnior, R. C. A. D. Silva, Marcelo Souza Santos, D. Albuquerque, H. Almeida, Danilo F. S. Santos","doi":"10.1109/ICCE53296.2022.9730757","DOIUrl":null,"url":null,"abstract":"In the Internet of Things (IoT) scenario, the distributed cross-domain nature of microservices needs secure token service (STS), key management and encryption services for authentication and authorization, and secure communication protocols. Similarly, the nature of clustered containers (in which microservices are implemented) calls for secure service discovery. The availability requirement calls for: (a) resiliency techniques, such as load balancing, circuit breaking, and throttling, and (b) continuous monitoring (for the health of the service). The service mesh is the best-known approach that can facilitate the specification of these requirements at a level of abstraction such that it can be uniformly and consistently defined while also being effectively implemented without making changes to individual microservice code. The purpose of this work is to provide deployment guidance for a robust security infrastructure for supporting microservices-based applications.","PeriodicalId":350644,"journal":{"name":"2022 IEEE International Conference on Consumer Electronics (ICCE)","volume":"69 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-01-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE International Conference on Consumer Electronics (ICCE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCE53296.2022.9730757","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

In the Internet of Things (IoT) scenario, the distributed cross-domain nature of microservices needs secure token service (STS), key management and encryption services for authentication and authorization, and secure communication protocols. Similarly, the nature of clustered containers (in which microservices are implemented) calls for secure service discovery. The availability requirement calls for: (a) resiliency techniques, such as load balancing, circuit breaking, and throttling, and (b) continuous monitoring (for the health of the service). The service mesh is the best-known approach that can facilitate the specification of these requirements at a level of abstraction such that it can be uniformly and consistently defined while also being effectively implemented without making changes to individual microservice code. The purpose of this work is to provide deployment guidance for a robust security infrastructure for supporting microservices-based applications.
基于微服务的可扩展安全体系结构
在物联网(IoT)场景下,微服务的分布式跨域特性需要安全令牌服务(STS)、用于认证和授权的密钥管理和加密服务以及安全通信协议。类似地,集群容器(微服务在其中实现)的本质要求安全的服务发现。可用性需求需要:(a)弹性技术,例如负载平衡、断路和节流,以及(b)持续监控(针对服务的运行状况)。服务网格是最著名的方法,它可以在抽象层次上促进这些需求的规范,这样就可以统一和一致地定义需求,同时也可以有效地实现,而无需更改单个微服务代码。这项工作的目的是为支持基于微服务的应用程序的健壮的安全基础设施提供部署指导。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信