• DocumentCode
    2922020
  • Title

    SOA-Aware Authorization Control

  • Author

    Emig, Christian ; Schandua, Heiko ; Abeck, Sebastian

  • Author_Institution
    Universitat Karlsruhe (TH), Germany
  • fYear
    2006
  • fDate
    Oct. 2006
  • Firstpage
    62
  • Lastpage
    62
  • Abstract
    The question how to handle authorization of digital identities in a service-oriented architecture (SOA) remains an open issue. In this paper we present a design pattern for the integration of legacy systems with SOA using out-of-the-box (unmodified) application servers and discuss how the architecture has to be extended by an Identity Management (IdM) infrastructure. We claim that the IdM infrastructure itself must be designed in a service-oriented way to fit into the overall SOA approach. We introduce a possibility how to decouple the policy enforcement point from the application server and propose an architectural design pattern to seamlessly integrate the SOA¿s business-related functionality and the IdM infrastructure. An implementation case study illustrates how to apply the invocation pattern for secured web services.
  • Keywords
    Application software; Authorization; Identity management systems; Investments; Protection; Protocols; Security; Semiconductor optical amplifiers; Service oriented architecture; Web services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Engineering Advances, International Conference on
  • Conference_Location
    Tahiti
  • Print_ISBN
    0-7695-2703-5
  • Type

    conf

  • DOI
    10.1109/ICSEA.2006.261318
  • Filename
    4031847