To address the scalability and identity federation problems of the traditional single sign-on system, the proposed scheme divides the security systems into different security domains. Each security domain has its own ...To address the scalability and identity federation problems of the traditional single sign-on system, the proposed scheme divides the security systems into different security domains. Each security domain has its own security servers and service providers, and there are trust relationships between different security domains for identity federation. The security server is responsible for authentication and authorization inside the domain, and offers identity federation capability for different domains. The security assertion markup language (SAML) assertion is used as security token in the system for authentication, authorization, and identity federation. The design of the proposed single sign-on process is based on web service security framework and multiple security domains, and the authorization is always deployed in the local area inside the service provider' s security domain, which enables web service clients, both inside and outside their security domains, to access the services in a simple, scalable, standard and secure way.展开更多
Service-oriented business process generation is a key activity in the ServiceOriented Architecture(SOA)business lifecycle,and most of the other activities such as application execution depend on the business process b...Service-oriented business process generation is a key activity in the ServiceOriented Architecture(SOA)business lifecycle,and most of the other activities such as application execution depend on the business process being developed.After the business requirements are acquired,a developer has to use specific programming technologies to orchestrate web services to generate a deployable business process.It is time-consuming to specify all the business processes from lowlevel web services,especially for an enterprise that focuses on a series of similar businesses.This paper proposes a rapid service-oriented business process generation method with domain-specific assets specified in ontology systems.Assets with different levels of granularity are reused to refine the high level business process framework for executable business processes using the Business Process Executional Language(BPEL).The new methodology significantly simplifies service-oriented business process generation by reusing assets to construct business processes.A business process generation tool is also implemented to support the efficient visual design of SOA processes with the proposed method.This paper verifies the proposed method using a shipment tracking case.The studies show that the number of reusable assets increases significantly as these projects progress,and the business process generation speed also increases at the same time.展开更多
基金The National Natural Science Foundation of China(No60673054)
文摘To address the scalability and identity federation problems of the traditional single sign-on system, the proposed scheme divides the security systems into different security domains. Each security domain has its own security servers and service providers, and there are trust relationships between different security domains for identity federation. The security server is responsible for authentication and authorization inside the domain, and offers identity federation capability for different domains. The security assertion markup language (SAML) assertion is used as security token in the system for authentication, authorization, and identity federation. The design of the proposed single sign-on process is based on web service security framework and multiple security domains, and the authorization is always deployed in the local area inside the service provider' s security domain, which enables web service clients, both inside and outside their security domains, to access the services in a simple, scalable, standard and secure way.
基金supported by the National Natural Science Foundation of China under GrantNo.61003067the National Basic ResearchProgram(973 Program)under Grants No.2013CB329102,No.2011CB302704the National Natural Science Foundation of Chinaunder Grants No.61132001,No.61171102,No.61001118
文摘Service-oriented business process generation is a key activity in the ServiceOriented Architecture(SOA)business lifecycle,and most of the other activities such as application execution depend on the business process being developed.After the business requirements are acquired,a developer has to use specific programming technologies to orchestrate web services to generate a deployable business process.It is time-consuming to specify all the business processes from lowlevel web services,especially for an enterprise that focuses on a series of similar businesses.This paper proposes a rapid service-oriented business process generation method with domain-specific assets specified in ontology systems.Assets with different levels of granularity are reused to refine the high level business process framework for executable business processes using the Business Process Executional Language(BPEL).The new methodology significantly simplifies service-oriented business process generation by reusing assets to construct business processes.A business process generation tool is also implemented to support the efficient visual design of SOA processes with the proposed method.This paper verifies the proposed method using a shipment tracking case.The studies show that the number of reusable assets increases significantly as these projects progress,and the business process generation speed also increases at the same time.