Managing Security Policy in a Large Distributed Web Services Environment

  • Authors:
  • Symon Chang;Qiming Chen;Meichun Hsu

  • Affiliations:
  • -;-;-

  • Venue:
  • COMPSAC '03 Proceedings of the 27th Annual International Conference on Computer Software and Applications
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

Effectively managing security policies in a largedistributed Web Services environment is the key tosecure e-business transactions. Security policy mustensure the end-to-end agreement for many-to-manyinteroperation; ensure the versioning interoperabilityand privacy of collaborating partners; and ensurethe dynamic establishment of security policies becauseany statically defined security policy tends to beunsecured after a certain period of time. The traditionalsecurity policy configuration mechanisms, eitherthe local configuration mechanism or the centralizedconfiguration mechanism, cannot fully meet theabove requirements.In this paper we describe a solution for managingsecurity policies in a collaborative Web Services environment.This solution is based on ebXML CPP/CPAmodel and uses Interoperability Contract Document(ICD). It allows the collaboration parties to establishsecurity policy dynamically for each individual interoperation;makes the selected policy confidential; andaddresses the software, message, and policy versioningand interoperability issues. Our experience revealsthe advantages of this approach over others.