Towards a Framework of Authentication and Authorization Patterns for Ensuring Availability in Service Composition

  • Authors:
  • Judith E. Y. Rossebo;Rolv Braek

  • Affiliations:
  • NTNU, Department of Telematics, and Telenor R&D, N-1331 Fornebu, Norway;NTNU, Department of Telematics N-7491 Trondheim, Norway

  • Venue:
  • ARES '06 Proceedings of the First International Conference on Availability, Reliability and Security
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Securing availability of applications and services is increasingly important for provisioning services in today's and future networks and systems. For fulfilling user expectations, availability depends more and more on the characteristics and requirements of the services themselves and the different requirements of certain users. In order to address service availability, we see availability as a composite notion consisting of the ability to ensure access for authorized users only, and the property of being on hand and useable when needed. Service composition is an approach to incremental service development contributing to rapid service design and development. This paper presents a set of authentication and authorization patterns addressing the aspect of ensuring access to authorized users only in service composition. We provide a framework and classification of these patterns, and we demonstrate how the patterns can be composed with services using a policy-driven approach.