期刊文献+

面向跨企业多方协同应用的Web服务安全模型 被引量:4

Web Service Security Model for Cross-enterprise Multiparty Collaboration Application
下载PDF
导出
摘要 现有的Web服务安全工具仅提供单个服务的安全策略配置功能,忽略了业务流程层面的安全需求。为此,提出一种面向跨企业多方协同应用的Web服务安全模型,将Web服务安全建模、部署与监控过程,融合到企业业务流程管理过程中。在此基础上构造基于Secure-WSCDL的建模工具、转换工具和监控工具,实现SOA架构下业务模型与安全建模在软件工程生命周期中的同步。通过简化的国际贸易进出口流程实例,验证了该模型与相应工具的有效性。 Web service security tools nowadays provide security configuration functionality at single Web services level,neglecting security requirement from business process layer.A Web service security framework towards multi-party collaboration application is proposed in this paper,which incorporates the enterprise business process management with security processes including security modeling,deployment and monitoring.Corresponding modeling tools,converting tools and monitoring tools based on Secure-WSCDL are constructed,synchronizing business model and security model throughout the entire software engineering lifecycle in SOA architecture.It verifies the effectiveness of the model and the tools by the simplified international trade import and export process instance.
作者 阮彤 金志超
出处 《计算机工程》 CAS CSCD 2013年第2期55-60,66,共7页 Computer Engineering
基金 国家"十一五"科技支撑计划基金资助重点项目"国际贸易经贸合作与流通促进关键技术研究"(2009BAH46B03)
关键词 WEB服务 Web服务编排描述语言 消息交换模式 Web服务安全策略 Web服务安全联邦 电子商务 Web service Web Service Choreography Description Language(WS-CDL) Message Exchange Pattern(MEP) Web service security policy Web service security federation e-commerce
  • 相关文献

参考文献1

二级参考文献5

  • 1Kulkarni D, Tripathi A. Context-aware Role-based Access Control in Pervasive Computing Systems[C]//Proc. of Symposium on Access Control Models and Technologies. Estes Park, CO, USA: ACM Press, 2008: 113-122.
  • 2Coetzee M, Eloff J H P. A Trust and Context-aware Access Control Model for Web Services Conversations[M]. Berlin, Germany: Springer, 2007.
  • 3Bertino E, Squicciarini A C, Paloscia I, et al. Ws-AC: A Fine Grained Access Control System for Web Services[C]//Proc of Conf. on World Wide Web Internet and Web Information Systems. New York, USA: ACM Press, 2005.
  • 4Raymond Y K. Lan Towards a Web Services and Intelligent Agents-based Negotiation System for B2B eCommerce[J]. Electronic Commerce Research and Applications, 2007, 6(3): 260-266.
  • 5努尔买买提.黑力力,罗振兴,林作铨.基于XACML的访问控制与RBAC限制[J].计算机工程,2008,34(8):19-21. 被引量:3

共引文献2

同被引文献24

引证文献4

二级引证文献17

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部