Design and implementation of extensible middleware for non-repudiable interactions

نویسنده

  • Paul Fletcher Robinson
چکیده

Non-repudiation is an aspect of security that is concerned with the creation of irrefutable audits ofan interaction. Ensuring the audit is irrefutable and verifiable by a third party is not a trivial task.A lot of supporting infrastructure is required which adds large expense to the interaction. Thisinfrastructure comprises, (i) a non-repudiation aware run-time environment, (ii) several purposebuilt trusted services and (iii) an appropriate non-repudiation protocol. This thesis presents designand implementation of such an infrastructure. The runtime environment makes use of several trustedservices to achieve external verification of the audit trail. Non-repudiation is achieved by executingfair non-repudiation protocols. The Fairness property of the non-repudiation protocol allows aparticipant to protect their own interests by preventing any party from gaining an advantage bymisbehaviour. The infrastructure has two novel aspects; extensibility and support for automatedimplementation of protocols.Extensibility is achieved by implementing the infrastructure in middleware and by presenting alarge variety of non-repudiable business interaction patterns to the application (a non-repudiableinteraction pattern is a higher level protocol composed from one or more non-repudiation proto-cols). The middleware is highly configurable allowing new non-repudiation protocols and interactionpatterns to be easily added, without disrupting the application.This thesis presents a rigorous mechanism for automated implementation of non-repudiationprotocols. This ensures that the protocol being executed is that which was intended and verifiedby the protocol designer. A family of non-repudiation protocols are taken and inspected. Thisinspection allows a set of generic finite state machines to be produced. These finite state machinescan be used to maintain protocol state and manage the sending and receiving of appropriate protocolmessages.A concrete implementation of the run-time environment and the protocol generation techniques ispresented. This implementation is based on industry supported Web service standards and services.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Design and Implementation of Web Services Middleware to Support Fair Non-Repudiable Interactions

The use of open, Internet-based communications for business-to-business (B2B) interactions requires accountability for and acknowledgment of the actions of participants. Accountability and acknowledgment can be achieved by the systematic maintenance of an irrefutable audit trail to render the interaction non-repudiable. To safeguard the interests of each party, the mechanisms used to meet this ...

متن کامل

Middleware support for non-repudiable business-to-business interactions

The wide variety of services and resources available over the Internet presents new opportunities for organisations to collaborate to reach common goals. For example, business partners wish to access each other’s services and share information along the supply chain in order to compete more successfully in the delivery of goods or services to the ultimate customer. This can lead to the investme...

متن کامل

Middleware Support for Non-repudiable Transactional Information Sharing between Enterprises

Enterprises increasingly use the Internet to offer their own services and to utilise the services of others. An extension of this trend is Internet-based collaboration between enterprises to form virtual enterprises for the delivery of goods or services. Effective formation of a virtual enterprise will require information sharing across organisational boundaries. Despite the requirement to shar...

متن کامل

Middleware For Fair Non-repudiable Interactions

The use of open, Internet-based communications for business-to-business (B2B) interactions requires accountability for and acknowledgment of the actions of participants. Accountability and acknowledgment can be achieved by the systematic maintenance of an irrefutable audit trail to render the interaction non-repudiable. To safeguard the interests of each party, the mechanisms used to meet this ...

متن کامل

Security and Trust in Composite Services

The wide variety of services and resources available over theInternet presents new opportunities to create value added, inter-organisational Composite Services (CSs) from multiple existing services.The resulting CS may involve close interaction between the constituentservices of participating organisations. In order to preserve theirautonomy and privacy, each organisation ne...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006