Title :
Secure Enterprise Services Consumption for SaaS Technology Platforms
Author :
Karabulut, Yuecel ; Nassi, Ike
Author_Institution :
SAP Res. Center Palo Alto, Palo Alto, CA
fDate :
March 29 2009-April 2 2009
Abstract :
Over recent years there has been increased level of discussion on utility pricing for software. The focus of these discussions is to create new operating cost models where the unit costs are directly tied to the business operations to which they contribute. While creating a fine-grained operating cost model is very important for software solutions such as SaaS, the anticipated technology platforms will need to rely on a set of security mechanisms in order to provide a secure and trustworthy service consumption environment. We present an architecture for secure enterprise services consumption management system and a protocol for secure service consumption for service-oriented technology platforms. Our approach is performance sensitive and utilizes a novel combination of asymmetric and symmetric cryptography, and capability based access control. Access to technology platform services is regulated based on the permissions encoded in cryptographic capability tokens. In this paper we report a work in progress.
Keywords :
authorisation; business process re-engineering; cryptography; software architecture; SaaS technology; asymmetric cryptography; capability based access control; cryptographic capability tokens; fine-grained operating cost model; secure enterprise services consumption; security mechanisms; service-oriented technology platforms; symmetric cryptography; trustworthy service consumption; utility pricing; Access control; Access protocols; Computer architecture; Costs; Cryptographic protocols; Cryptography; Permission; Pricing; Security; Technology management; SaaS; authentication; authorization; security;
Conference_Titel :
Data Engineering, 2009. ICDE '09. IEEE 25th International Conference on
Conference_Location :
Shanghai
Print_ISBN :
978-1-4244-3422-0
Electronic_ISBN :
1084-4627
DOI :
10.1109/ICDE.2009.150