Model-Driven Security Engineering for Trust Management in SECTET
نویسندگان
چکیده
Service Oriented Architectures with underlying technologies like web services and web services orchestration have opened the door to a wide range of novel application scenarios, especially in the context of inter-organizational cooperation. One of the remaining obstacles for a widespread use of these techniques is security. Companies and organizations open their systems and core business processes to partners only if a high level of trust can be guaranteed. The emergence of web services security standards provides a valuable and effective paradigm for addressing the security issues arising in the context of inter-organizational cooperation. The low level of abstraction of these standards is, however, still an unresolved issue which makes them inaccessible to the domain expert and remains a major obstacle when aligning security objectives with the customer needs. Their complexity makes implementation easily prone of error. The SECTET – a model-driven security engineering framework for B2B-workflows – facilitates the design and implementation of secure inter-organizational workflows. This contribution has three objectives. First we present a high-level domain specific language – called SECTET-PL. Being part of the SECTET-framework, SECTET-PL is a policy language influenced by Object Constraint Language and interpreted in the context of UML models. We then detail the Meta Object Facility based metamodels for the integration of business requirements with the security requirements. Finally, using Model Driven Architecture paradigm, we describe the transformation of high-level security models to low-level web services standard artefacts with the help of Eclipse Modelling Framework and OpenArchitectureWare.
منابع مشابه
Security engineering for service-oriented architectures
The book is divided into three main parts. In the first part, the necessary foundations are introduced. Since the focus of the book relies on the model-driven development of secured SOAP-based Web Services, the initial part deals with SOAP and the related standards and technology stack as well as the model-driven software development methodology. In the second part, the design and realisation o...
متن کاملAdvancing a New Software Engineering Discipline
In this paper we present SECTET, a tool-based framework for the design, implementation and quality assurance of web service based applications. Main focus in SECTET is put on the design of inter-organizational workflows, the model driven realization of security aspects and testing of workflows. We present an overview of the model views, the design activities and the underlying architecture.
متن کاملSeAAS - A Reference Architecture for Security Services in SOA
Decentralized security models and distributed infrastructures of scenarios based on Service Oriented Architectures make the enforcement of security policies a key challenge – all the more so for business processes spanning over multiple enterprises. The current practice to implement security functionality exclusively at the endpoint places a significant processing burden on the endpoint, render...
متن کاملA Novel Trust Management Model in the Social Internet of Things
The Internet of Things (IoT) and social networking integration, create a new concept named Social Internet of Things (SIoT) according to which the things are able to autonomously establish social relationships with regard to the owners. Things in SIoT operate according to a service-oriented architecture. There may be misbehaving owners and consequently misbehaving devices that can perform harmf...
متن کاملA systematic review of security requirements engineering
a r t i c l e i n f o One of the most important aspects in the achievement of secure software systems in the software development process is what is known as Security Requirements Engineering. However, very few reviews focus on this theme in a systematic, thorough and unbiased manner, that is, none of them perform a systematic review of security requirements engineering, and there is not, there...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- JSW
دوره 2 شماره
صفحات -
تاریخ انتشار 2007