Lightweight information flow control for web services

  • Authors:
  • Bartosz Brodecki;Michał Kalewski;Piotr Sasak;Michał Szychowiak

  • Affiliations:
  • Poznań University of Technology, Poznań, Poland;Poznań University of Technology, Poznań, Poland;Poznań University of Technology, Poznań, Poland;Poznań University of Technology, Poznań, Poland

  • Venue:
  • PPAM'11 Proceedings of the 9th international conference on Parallel Processing and Applied Mathematics - Volume Part II
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents a concept of incorporating information flow control (IFC) mechanisms into service-oriented systems. As opposed to existing IFC proposals, commonly imposing requirements hard or impossible to achieve in service-oriented environments (such as analysis of the application code), our solution fully complies with the Service Oriented Architecture (SOA) model. We present how IFC can be managed in an SOA system by using ORCA security policy language. We also describe two possible implementations of such SOA-specific IFC mechanisms using cryptographic keys and poly-instantiated web services.