xESB: An enterprise service bus for access and usage control policy enforcement

18Citations
Citations of this article
16Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Enforcing complex policies that span organizational domains is an open challenge. Current work on SOA policy enforcement splits security in logical components that can be distributed across domains, but does not offer any concrete solution to integrate this security functionality so that it works across security services for organization-wide policies. In this paper, we propose xESB, an enhanced version of an Enterprise Message Bus (ESB), where we monitor and enforce preventive and reactive policies, both for access control and usage control policies, and both inside one domain and between domains. In addition, we introduce indicators that help SOA administrators assess the effectiveness of their policies. Our performance measurements show that policy enforcement at the ESB level comes with only moderate penalties.

Cite

CITATION STYLE

APA

Gheorghe, G., Neuhaus, S., & Crispo, B. (2010). xESB: An enterprise service bus for access and usage control policy enforcement. In IFIP Advances in Information and Communication Technology (Vol. 321, pp. 63–78). Springer Science and Business Media, LLC. https://doi.org/10.1007/978-3-642-13446-3_5

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free