{"title":"An architecture for certification-aware service discovery","authors":"M. Bezzi, A. Sabetta, G. Spanoudakis","doi":"10.1109/IWSSCLOUD.2011.6049020","DOIUrl":null,"url":null,"abstract":"Service-orientation is an emerging paradigm for building complex systems based on loosely coupled components, deployed and consumed over the network. Despite the original intent of the paradigm, its current instantiations are limited to a single trust domain (e.g., a single organization) One of the main reasons for this is the trust gap that normally arises when software services, offered by previously unknown providers, are to be selected at run-time, without any human intervention. The idea of machine-readable security certificates (called asserts) paves the way to automated reasoning about security properties of services. Similarly to current security certification schemes, the assessment of the security properties of a service is delegated to an independent third party (certification authority), who issues a corresponding assert, bound to the service. Building on the assert concept, this paper describes our proposal for a modular architecture to realise a certification-aware service discovery framework. The architecture supports the discovery of single services based on certified security properties, as well as the dynamic synthesis of service compositions that satisfy the required security properties.","PeriodicalId":396741,"journal":{"name":"2011 1st International Workshop on Securing Services on the Cloud (IWSSC)","volume":"53 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-10-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"11","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2011 1st International Workshop on Securing Services on the Cloud (IWSSC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IWSSCLOUD.2011.6049020","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 11
Abstract
Service-orientation is an emerging paradigm for building complex systems based on loosely coupled components, deployed and consumed over the network. Despite the original intent of the paradigm, its current instantiations are limited to a single trust domain (e.g., a single organization) One of the main reasons for this is the trust gap that normally arises when software services, offered by previously unknown providers, are to be selected at run-time, without any human intervention. The idea of machine-readable security certificates (called asserts) paves the way to automated reasoning about security properties of services. Similarly to current security certification schemes, the assessment of the security properties of a service is delegated to an independent third party (certification authority), who issues a corresponding assert, bound to the service. Building on the assert concept, this paper describes our proposal for a modular architecture to realise a certification-aware service discovery framework. The architecture supports the discovery of single services based on certified security properties, as well as the dynamic synthesis of service compositions that satisfy the required security properties.