End-to-End Security for Enterprise Mashups

  • Authors:
  • Florian Rosenberg;Rania Khalaf;Matthew Duftler;Francisco Curbera;Paula Austel

  • Affiliations:
  • Distributed Systems Group, Technical University Vienna, Vienna, Austria;IBM T.J. Watson Research Center, Hawthorne, NY 10532;IBM T.J. Watson Research Center, Hawthorne, NY 10532;IBM T.J. Watson Research Center, Hawthorne, NY 10532;IBM T.J. Watson Research Center, Hawthorne, NY 10532

  • Venue:
  • ICSOC-ServiceWave '09 Proceedings of the 7th International Joint Conference on Service-Oriented Computing
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Mashups are gaining momentum as a means to develop situational Web applications by combining different resources (services, data feeds) and user interfaces. In enterprise environments, mashups are recently used for implementing Web-based business processes, however, security is a major concern. Current approaches do not allow the mashup to securely consume services with diverse security requirements without sharing the credentials or hard-coding them in the mashup definition. In this paper, we present a solution to integrate security concerns into an existing enterprise mashup platform. We provide an extension to the language and runtime and propose a Secure Authentication Service (SAS) to seamlessly facilitate secure authentication and authorization of end-users with the services consumed in the mashup.