PBA4WSSP: a policy-based architecture for web services security processing

  • Authors:
  • Hao Zeng;Dianfu Ma;Yongwang Zhao;Zhuqing Li

  • Affiliations:
  • Key Laboratory of Software Development Environment, School of Computer Science and Engineering, Beihang University, Beijing, China;Key Laboratory of Software Development Environment, School of Computer Science and Engineering, Beihang University, Beijing, China;Key Laboratory of Software Development Environment, School of Computer Science and Engineering, Beihang University, Beijing, China;Key Laboratory of Software Development Environment, School of Computer Science and Engineering, Beihang University, Beijing, China

  • Venue:
  • Service Oriented Computing and Applications
  • Year:
  • 2014

Quantified Score

Hi-index 0.00

Visualization

Abstract

Due to the dynamic, heterogeneous and interorganizational nature, different web services and different ports or operations in the same service, even the same services at different times may have their different security requirements because of their different security domains and different business backgrounds. How to design a flexible, fine-grained and comprehensive architecture for web services security processing has become a matter of great urgency. However, no ideal solutions have been worked out for these problems. As a result of our study, we have presented in this paper a policy-based architecture termed policy-based architecture for web services security processing (PBA4WSSP) to meet the dynamic, complete and fine-grained security requirements. In PBA4WSSP, the processing of all security problems is based on security policy in service stage to support flexibly security configuration. Moreover, we have designed a service policy model to describe the fine-grained security requirements. And the conversion method between security policy model and security policy expression has also been described. In addition, a staged complete security processing architecture is provided to reduce the dependency among protocol implementations. Furthermore, with PBA4WSSP, a web service security module has been designed and implemented as well. Eventually, the performance evaluation results amply demonstrate that our system is flexible and usable.