DocumentCode
3125865
Title
An Application Security Framework for SOA-Based Mission Data Systems
Author
Fischer, Daniel ; Sarkarati, Mehran ; Spada, Mariella ; Michelbach, Thomas ; Urban, Wenzel ; Tueffers, Christian
Author_Institution
Eur. Space Oper. Centre, Eur. Space Agency, Darmstadt, Germany
fYear
2011
fDate
2-4 Aug. 2011
Firstpage
53
Lastpage
60
Abstract
ESA is developing, deploying, and operating a wide variety of mission data systems. These are mainly used for the command & control of spacecraft and the exploitation and dissemination of space-based services to end users. A new ESA activity, the European Space Situational Awareness (SSA) Initiative, requires a novel generation of mission data systems to be developed. These systems are based on a service-oriented architecture (SOA) and capable of supporting a large system-of-systems environment. At the same time, information security is an area of growing concern in the space business and among space agencies. Especially in the area of SOA-based environments, where interconnectivity of components is a core principle, an efficient and robust security concept needs to be put in place to ensure secure mission operations. In this paper, we describe an application security framework for SOA-based mission data systems. This framework increases significantly the robustness and security of web services and web applications through use of a Secure Software Development Lifecycle (SSDLC) and provision of tools & templates for SSA mission data system developers. We are confident that the application security framework will drastically improve the security and robustness of SOA-based mission data systems that will be used in the European SSA Initiative and other ESA projects, while at the same time keeping the related additional effort minimal.
Keywords
Web services; command and control systems; safety-critical software; security of data; service-oriented architecture; space vehicles; European space situational awareness; SOA-based mission data systems; Web applications; Web services; application security framework; command & control; component interconnectivity; information security; secure software development lifecycle; service-oriented architecture; space agencies; space-based services; spacecraft; system-of-systems; Computer architecture; Data systems; Europe; Programming; Risk management; Security; Service oriented architecture; Information Security; Secure Software Development Lifecycle; Service-Oriented Architectures; Software Engineering; System-of-Systems;
fLanguage
English
Publisher
ieee
Conference_Titel
Space Mission Challenges for Information Technology (SMC-IT), 2011 IEEE Fourth International Conference on
Conference_Location
Palo Alto, CA
Print_ISBN
978-1-4577-0712-4
Electronic_ISBN
978-1-4577-0713-1
Type
conf
DOI
10.1109/SMC-IT.2011.22
Filename
6007775
Link To Document