Ensuring trust in service consumption through security certification

QASBA '11 Pub Date : 2011-09-14 DOI:10.1145/2031746.2031758
M. Bezzi, Samuel Paul Kaluvuri, A. Sabetta
{"title":"Ensuring trust in service consumption through security certification","authors":"M. Bezzi, Samuel Paul Kaluvuri, A. Sabetta","doi":"10.1145/2031746.2031758","DOIUrl":null,"url":null,"abstract":"The service-based paradigm is enabling new models of software provisioning based on cloud architectures. An increasing number of organizations are either providing their software as a service or acting as enablers by providing platforms on which service providers can offer their services. However the service implementations and the characteristics of the underlying cloud architectures are often opaque to the service consumers. The resulting deficit of trust on the security of such services is hampering the adoption of these new software paradigms by the industry.\n In this paper, we discuss an approach for security certification of services that can help fill this trust deficit, and we analyze the challenges that we face in realizing this approach. In particular, we concentrate on the problem of ensuring a robust binding between a security certificate and the corresponding service, outlining some possible approaches to tackle this issue.","PeriodicalId":357051,"journal":{"name":"QASBA '11","volume":"77 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-09-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"QASBA '11","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2031746.2031758","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9

Abstract

The service-based paradigm is enabling new models of software provisioning based on cloud architectures. An increasing number of organizations are either providing their software as a service or acting as enablers by providing platforms on which service providers can offer their services. However the service implementations and the characteristics of the underlying cloud architectures are often opaque to the service consumers. The resulting deficit of trust on the security of such services is hampering the adoption of these new software paradigms by the industry. In this paper, we discuss an approach for security certification of services that can help fill this trust deficit, and we analyze the challenges that we face in realizing this approach. In particular, we concentrate on the problem of ensuring a robust binding between a security certificate and the corresponding service, outlining some possible approaches to tackle this issue.
通过安全认证确保对服务消费的信任
基于服务的范例支持基于云架构的软件供应的新模型。越来越多的组织要么将他们的软件作为服务来提供,要么通过提供服务提供者可以提供服务的平台来充当推动者。然而,服务实现和底层云架构的特征对于服务消费者来说通常是不透明的。由此导致的对这些服务安全性的信任缺失阻碍了行业对这些新软件范例的采用。在本文中,我们讨论了一种用于服务安全认证的方法,该方法可以帮助填补这种信任缺陷,并分析了我们在实现该方法时面临的挑战。我们特别关注确保安全证书和相应服务之间的健壮绑定的问题,概述了解决此问题的一些可能方法。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信