• DocumentCode
    134481
  • Title

    Anonymity of web service invocations

  • Author

    Davidoaia, Bogdan ; Leordeanu, Catalin ; Cristea, Valentin

  • Author_Institution
    Fac. of Autom. Control & Comput., Univ. `Politeh.´ of Bucharest, Bucharest, Romania
  • fYear
    2014
  • fDate
    4-6 Sept. 2014
  • Firstpage
    369
  • Lastpage
    376
  • Abstract
    Service Oriented Architectures offer modularity and flexibility, while maintaining a relatively simple communication model. Security is still needed as messages can be intercepted by a potential attacker and the service interaction can be compromised. One research direction to achieve this is to hide the identity of the communication parties by assuring sender and receiver anonymity and by protecting the message content through encryption. This paper describes a solution to ensure anonymous web service access through the use of a proxy-based system. This solution protects the identity of a set of web services by mediating all web service invocation requests and imposing a set of security policies. Since the proxy manages multiple web service instances deployed on multiple devices, it also implements a set of load balancing policies, which help improve performance and prevent overloading. We tested the proposed solution and analyzed the overhead introduced by the proxy within the web service invocation process. Furthermore, we present an analysis of the overhead introduced by the additional security features.
  • Keywords
    Web services; cryptography; data privacy; resource allocation; service-oriented architecture; Web service invocation anonymity; Web service invocation request; anonymous Web service access; communication model; communication parties; encryption; identity hiding; load balancing policies; message content protection; message interception; multiple Web service instance management; overloading prevention; performance improvement; potential attacker; proxy-based system; receiver anonymity; security features; security policies; sender anonymity; service interaction; service oriented architecture; Load management; Receivers; Security; Servers; Service-oriented architecture; Simple object access protocol;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Intelligent Computer Communication and Processing (ICCP), 2014 IEEE International Conference on
  • Conference_Location
    Cluj Napoca
  • Print_ISBN
    978-1-4799-6568-7
  • Type

    conf

  • DOI
    10.1109/ICCP.2014.6937023
  • Filename
    6937023