A certification-aware service-oriented architecture

1Citations
Citations of this article
15Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The widespread development of Service-Oriented Architecture (SOA) and web services is changing the traditional view of information technology. Today, software applications are increasingly distributed and consumed as a service, and business processes are implemented by selecting and composing services provided by different suppliers at run-time and with a minimal human intervention. In this scenario, where services are usually selected on the basis of clients' functional preferences, the risk of providing powerful but insecure applications raises, and the problem of guaranteeing and preserving the security of services and business processes becomes stringent. To this aim, we put forward the idea that security certification techniques can be adopted to provide the evidence that a service system has some security properties and behaves as expected. However, existing security certification techniques are not well-suited to the service scenario, since they are designed for static and monolithic software and then cannot support the intrinsic SOA dynamics. In this chapter, we discuss recent developments in the area of extending security certifications to web services. In particular, we first review current certification approaches, and highlight requirements and challenges for applying them to the service ecosystem. We then present an advanced methodology for security certification based on testing, as a crucial part of a novel approach for security certification developed in the context of the FP7 EU project Advanced Security Service cERTificate for SOA (ASSERT4SOA).

Cite

CITATION STYLE

APA

Anisetti, M., Ardagna, C. A., Bezzi, M., Damiani, E., Kaluvuri, S. P., & Sabetta, A. (2014). A certification-aware service-oriented architecture. In Advanced Web Services (Vol. 9781461475354, pp. 147–170). Springer New York. https://doi.org/10.1007/978-1-4614-7535-4_7

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free