DocumentCode :
3127628
Title :
Verifying the Consistency of Security Policies by Abstracting into Security Types
Author :
Ono, Kouichi ; Nakamura, Yuichi ; Satoh, Fumiko ; Tateishi, Takaaki
Author_Institution :
Tokyo Res. Lab., Tokyo
fYear :
2007
fDate :
9-13 July 2007
Firstpage :
497
Lastpage :
504
Abstract :
The service-oriented architecture (SOA) makes application development easier, because applications can be built from existing services with a bottom-up methodology. However, it is difficult to determine if a desired new service can be built from existing services. Not only the functional consistency of the existing services, but also the consistency of their non-functional (such as security) aspects must be verified. Message protection is an aspect of security. Every service needs an appropriate security policy defining the protection of messages exchanged between the parties to the service. Because of the intricacy of the Web services security policy language, it is difficult to verify the consistency of the security policies. We are developing a method to verify the consistency of security policies by abstracting them. Each security policy is abstracted, and then attached as a security type to the corresponding service in the application model. The security type denotes a security level for message protection. The security developer defines the possible abstraction methods. In this paper, we define the constraint of abstraction methods based on the semantics of the policy language. And also we state verifying the consistency of security types by using information flow analysis.
Keywords :
Web services; program verification; security of data; software architecture; Web services security policy language; message protection; service-oriented architecture; software verification; Application software; Buildings; Computer networks; Information analysis; Information security; Laboratories; Protection; Service oriented architecture; Web and internet services; Web services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Web Services, 2007. ICWS 2007. IEEE International Conference on
Conference_Location :
Salt Lake City, UT
Print_ISBN :
0-7695-2924-0
Type :
conf
DOI :
10.1109/ICWS.2007.187
Filename :
4279636
Link To Document :
بازگشت