DocumentCode
134481
Title
Anonymity of web service invocations
Author
Davidoaia, Bogdan ; Leordeanu, Catalin ; Cristea, Valentin
Author_Institution
Fac. of Autom. Control & Comput., Univ. `Politeh.´ of Bucharest, Bucharest, Romania
fYear
2014
fDate
4-6 Sept. 2014
Firstpage
369
Lastpage
376
Abstract
Service Oriented Architectures offer modularity and flexibility, while maintaining a relatively simple communication model. Security is still needed as messages can be intercepted by a potential attacker and the service interaction can be compromised. One research direction to achieve this is to hide the identity of the communication parties by assuring sender and receiver anonymity and by protecting the message content through encryption. This paper describes a solution to ensure anonymous web service access through the use of a proxy-based system. This solution protects the identity of a set of web services by mediating all web service invocation requests and imposing a set of security policies. Since the proxy manages multiple web service instances deployed on multiple devices, it also implements a set of load balancing policies, which help improve performance and prevent overloading. We tested the proposed solution and analyzed the overhead introduced by the proxy within the web service invocation process. Furthermore, we present an analysis of the overhead introduced by the additional security features.
Keywords
Web services; cryptography; data privacy; resource allocation; service-oriented architecture; Web service invocation anonymity; Web service invocation request; anonymous Web service access; communication model; communication parties; encryption; identity hiding; load balancing policies; message content protection; message interception; multiple Web service instance management; overloading prevention; performance improvement; potential attacker; proxy-based system; receiver anonymity; security features; security policies; sender anonymity; service interaction; service oriented architecture; Load management; Receivers; Security; Servers; Service-oriented architecture; Simple object access protocol;
fLanguage
English
Publisher
ieee
Conference_Titel
Intelligent Computer Communication and Processing (ICCP), 2014 IEEE International Conference on
Conference_Location
Cluj Napoca
Print_ISBN
978-1-4799-6568-7
Type
conf
DOI
10.1109/ICCP.2014.6937023
Filename
6937023
Link To Document