向模型驱动安全性添加身份验证

Fumiko Satoh, Yuichi Nakamura, Koichi Ono
{"title":"向模型驱动安全性添加身份验证","authors":"Fumiko Satoh, Yuichi Nakamura, Koichi Ono","doi":"10.1109/ICWS.2006.25","DOIUrl":null,"url":null,"abstract":"As service-oriented architecture has become popular, security has been a critical issue in multiple security domains using the WS-security framework. The authentication requirements depend on the application semantics, but configuring authentication is very difficult for someone who is not a security expert, such as an application developer, because it is necessary to understand platform-specific security features and authentication mechanisms. To resolve these difficulties, we propose a framework for platform-independent security configuration based on the model driven architecture. In this paper, we introduce a security qualifier, which is an abstract annotation for specifying authenticated identity on a platform-independent model, and a security infrastructure model which is a model including the platform information required for creating security policies. These ideas make authentication configuration possible without understanding the platform-specific information, such as the federation of the security domain and the relationships of trust between the servers. Our framework allows a non-security expert to configure security easily. We show how to configure the authentication for an ID propagation scenario and discuss advantages of our framework compared to existing tools","PeriodicalId":408032,"journal":{"name":"2006 IEEE International Conference on Web Services (ICWS'06)","volume":"41 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2006-09-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"25","resultStr":"{\"title\":\"Adding Authentication to Model Driven Security\",\"authors\":\"Fumiko Satoh, Yuichi Nakamura, Koichi Ono\",\"doi\":\"10.1109/ICWS.2006.25\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"As service-oriented architecture has become popular, security has been a critical issue in multiple security domains using the WS-security framework. The authentication requirements depend on the application semantics, but configuring authentication is very difficult for someone who is not a security expert, such as an application developer, because it is necessary to understand platform-specific security features and authentication mechanisms. To resolve these difficulties, we propose a framework for platform-independent security configuration based on the model driven architecture. In this paper, we introduce a security qualifier, which is an abstract annotation for specifying authenticated identity on a platform-independent model, and a security infrastructure model which is a model including the platform information required for creating security policies. These ideas make authentication configuration possible without understanding the platform-specific information, such as the federation of the security domain and the relationships of trust between the servers. Our framework allows a non-security expert to configure security easily. We show how to configure the authentication for an ID propagation scenario and discuss advantages of our framework compared to existing tools\",\"PeriodicalId\":408032,\"journal\":{\"name\":\"2006 IEEE International Conference on Web Services (ICWS'06)\",\"volume\":\"41 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2006-09-18\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"25\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2006 IEEE International Conference on Web Services (ICWS'06)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICWS.2006.25\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2006 IEEE International Conference on Web Services (ICWS'06)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICWS.2006.25","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 25

摘要

随着面向服务的体系结构变得流行,在使用WS-security框架的多个安全领域中,安全性已经成为一个关键问题。身份验证需求取决于应用程序语义,但对于非安全专家(如应用程序开发人员)来说,配置身份验证非常困难,因为必须了解特定于平台的安全特性和身份验证机制。为了解决这些困难,我们提出了一个基于模型驱动架构的平台无关安全配置框架。在本文中,我们引入了一个安全限定符和一个安全基础结构模型,前者是用于在平台无关的模型上指定身份验证的抽象注释,后者是包含创建安全策略所需的平台信息的模型。这些思想使得无需了解特定于平台的信息(例如安全域的联合和服务器之间的信任关系)就可以进行身份验证配置。我们的框架允许非安全专家轻松配置安全性。我们将展示如何为ID传播场景配置身份验证,并讨论我们的框架与现有工具相比的优势
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Adding Authentication to Model Driven Security
As service-oriented architecture has become popular, security has been a critical issue in multiple security domains using the WS-security framework. The authentication requirements depend on the application semantics, but configuring authentication is very difficult for someone who is not a security expert, such as an application developer, because it is necessary to understand platform-specific security features and authentication mechanisms. To resolve these difficulties, we propose a framework for platform-independent security configuration based on the model driven architecture. In this paper, we introduce a security qualifier, which is an abstract annotation for specifying authenticated identity on a platform-independent model, and a security infrastructure model which is a model including the platform information required for creating security policies. These ideas make authentication configuration possible without understanding the platform-specific information, such as the federation of the security domain and the relationships of trust between the servers. Our framework allows a non-security expert to configure security easily. We show how to configure the authentication for an ID propagation scenario and discuss advantages of our framework compared to existing tools
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信