• DocumentCode
    3125865
  • Title

    An Application Security Framework for SOA-Based Mission Data Systems

  • Author

    Fischer, Daniel ; Sarkarati, Mehran ; Spada, Mariella ; Michelbach, Thomas ; Urban, Wenzel ; Tueffers, Christian

  • Author_Institution
    Eur. Space Oper. Centre, Eur. Space Agency, Darmstadt, Germany
  • fYear
    2011
  • fDate
    2-4 Aug. 2011
  • Firstpage
    53
  • Lastpage
    60
  • Abstract
    ESA is developing, deploying, and operating a wide variety of mission data systems. These are mainly used for the command & control of spacecraft and the exploitation and dissemination of space-based services to end users. A new ESA activity, the European Space Situational Awareness (SSA) Initiative, requires a novel generation of mission data systems to be developed. These systems are based on a service-oriented architecture (SOA) and capable of supporting a large system-of-systems environment. At the same time, information security is an area of growing concern in the space business and among space agencies. Especially in the area of SOA-based environments, where interconnectivity of components is a core principle, an efficient and robust security concept needs to be put in place to ensure secure mission operations. In this paper, we describe an application security framework for SOA-based mission data systems. This framework increases significantly the robustness and security of web services and web applications through use of a Secure Software Development Lifecycle (SSDLC) and provision of tools & templates for SSA mission data system developers. We are confident that the application security framework will drastically improve the security and robustness of SOA-based mission data systems that will be used in the European SSA Initiative and other ESA projects, while at the same time keeping the related additional effort minimal.
  • Keywords
    Web services; command and control systems; safety-critical software; security of data; service-oriented architecture; space vehicles; European space situational awareness; SOA-based mission data systems; Web applications; Web services; application security framework; command & control; component interconnectivity; information security; secure software development lifecycle; service-oriented architecture; space agencies; space-based services; spacecraft; system-of-systems; Computer architecture; Data systems; Europe; Programming; Risk management; Security; Service oriented architecture; Information Security; Secure Software Development Lifecycle; Service-Oriented Architectures; Software Engineering; System-of-Systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Space Mission Challenges for Information Technology (SMC-IT), 2011 IEEE Fourth International Conference on
  • Conference_Location
    Palo Alto, CA
  • Print_ISBN
    978-1-4577-0712-4
  • Electronic_ISBN
    978-1-4577-0713-1
  • Type

    conf

  • DOI
    10.1109/SMC-IT.2011.22
  • Filename
    6007775