• DocumentCode
    1155167
  • Title

    Dynamic Trust Management

  • Author

    Blaze, Matt ; Kannan, Sampath ; Lee, Insup ; Sokolsky, Oleg ; Smith, Jonathan M. ; Keromytis, Angelos D. ; Lee, Wenke

  • Volume
    42
  • Issue
    2
  • fYear
    2009
  • Firstpage
    44
  • Lastpage
    52
  • Abstract
    We continue to investigate the use of trust management techniques to specify dynamic policies in complex integrated service-oriented networks. For this work, we use the DoD GIG´s service-oriented architecture as a focal point. In this research´s initial phase, we are developing prototype dynamic trust management policy services for a service-oriented architecture. In our research´s next phase, we will develop and analyze policies with properties that maintain strict separation between services while allowing exceptions. Finally, we are developing improved trust management languages and systems that more explicitly support dynamic policies in service-oriented architectures, based on the semantic and performance experiences gained in the research´s first phases. Our focus will be twofold. First, we will explore adding trust-management language features that better support dynamic policies, based both on our experiences in the initial research and on the GIG´s specific requirements. Second, we will conduct experiments to measure the performance implications of incorporating the trust management layer in the various layers of such systems. A significant open research question is whether trust management is architecturally best implemented as a low-level operating system service, an application-layer service, or somewhere in between.
  • Keywords
    grid computing; security of data; software architecture; Global Information Grid; complex integrated service-oriented networks; dynamic trust management; service-oriented architecture; trust-management language; Access control; Context-aware services; Data security; Formal specifications; Image databases; Information security; Interconnected systems; Large-scale systems; Portable computers; Web services; Global Information Grid; service-oriented architecture; trust management; virtual private services;
  • fLanguage
    English
  • Journal_Title
    Computer
  • Publisher
    ieee
  • ISSN
    0018-9162
  • Type

    jour

  • DOI
    10.1109/MC.2009.51
  • Filename
    4781970