loading...
Logic-based Management of Security in Web Services
Salt Lake City, Utah, USA July 09-July 13
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/SCC.2007.77IEEE International Conference on Serv ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Christina Tziviskou, Politecnico di Milano, via Ponzio 34/5, Milano, Italy
Elisabetta Di Nitto, Politecnico di Milano, via Ponzio 34/5, Milano, Italy
The increasing use of the Web as the platform for delivering business processes arises the need to protect both sensitive data exchanged over the Internet and the applications using these data. In this context, authentication, integrity and confidentiality of exchanged messages are requested during interactions between processes, and are commonly called WS* specifications. In this paper, we propose a formal specification of the above security requirements and the corresponding assertions in the exchanged messages, built on the XSB logic programming language. Our framework analyzes the generated models and verifies that incoming messages fulfill the security requirements of a Web service. Furthermore, it verifies the compatibility between two policies, which is a significant condition in order to guarantee secure end-to-end SOAP invocations, and it is not currently supported by WS* specifications.
Citation:
Christina Tziviskou, Elisabetta Di Nitto, "Logic-based Management of Security in Web Services," scc, pp.228-235, IEEE International Conference on Services Computing (SCC 2007), 2007
Usage of this product signifies your acceptance of the Terms of Use.