loading...
Adding Authentication to Model Driven Security
Chicago, Illinois, USA September 18-September 22
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/ICWS.2006.25IEEE International Conference on Web ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Fumiko Satoh, IBM Tokyo Research Laboratory, Japan
Yuichi Nakamura, IBM Tokyo Research Laboratory, Japan
Koichi Ono, IBM Tokyo Research Laboratory, Japan
As Service-Oriented Architecture has become popular, security has been a critical issue in multiple security domains using the WS-Security framework. The authentication requirements depend on the application semantics, but configuring authentication is very difficult for someone who is not a security expert, such as an application developer, because it is necessary to understand platform-specific security features and authentication mechanisms. To resolve these difficulties, we propose a framework for platformindependent security configuration based on the Model Driven Architecture. In this paper, we introduce a security qualifier, which is an abstract annotation for specifying authenticated identity on a platform-independent model, and a Security Infrastructure Model which is a model including the platform information required for creating security policies. These ideas make authentication configuration possible without understanding the platform-specific information, such as the federation of the security domain and the relationships of trust between the servers. Our framework allows a non-security expert to configure security easily. We show how to configure the authentication for an ID propagation scenario and discuss advantages of our framework compared to existing tools.
Citation:
Fumiko Satoh, Yuichi Nakamura, Koichi Ono, "Adding Authentication to Model Driven Security," icws, pp.585-594, IEEE International Conference on Web Services (ICWS'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.