| A technical architecture for enforcing usage control requirements in service-oriented architectures |
| Full text |
Pdf
(648 KB)
|
Source
|
Workshop On Secure Web Services
archive
Proceedings of the 2007 ACM workshop on Secure web services
table of contents
Fairfax, Virginia, USA
SESSION: Session 1
table of contents
Pages: 18 - 25
Year of Publication: 2007
ISBN:978-1-59593-892-3
|
|
Authors
|
|
Agreiter Berthold
|
University of Innsbruck, Innsbruck, Austria
|
|
Muhammad Alam
|
University of Innsbruck, Innsbruck, Austria
|
|
Ruth Breu
|
University of Innsbruck, Innsbruck, Austria
|
|
Michael Hafner
|
University of Innsbruck, Innsbruck, Austria
|
|
Alexander Pretschner
|
ETH Zurich, Zurich, Switzerland
|
|
Jean-Pierre Seifert
|
University of Innsbruck, Austria, and Samsung Information Systems America, San Jose, CA
|
|
Xinwen Zhang
|
Samsung Information Systems America, San Jose, CA
|
|
| Sponsors |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 15, Downloads (12 Months): 148, Citation Count: 2
|
|
|
ABSTRACT
We present an approach to modeling and enforcing usage control requirements on remote clients in service-oriented architectures. Technically, this is done by leveraging a trusted software stack relying on a hardware-based root of trust and a trusted Java virtual machine to create a measurable and hence trust worthy client-side application environment. We define a model-driven approach to specifying remote policies that makes the technical intricacies of the target platform transparent to the policy modeler.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
SUN XACML Implementation. Available at sunxacml.sourceforge.net.
|
| |
2
|
Trusted computing group (tcg). https://www.trustedcomputinggroup.org/specs/.
|
| |
3
|
M. Alam, R. Breu, and M. Breu. Model Driven Security for Web Services (MDS4WS). In Proc. INMIC, 2004.
|
| |
4
|
M. Alam, M. Hafner, J.-P. Siefert, and X. Zhang. Extending SELinux Policy Model and Enforcement Architecture for Trusted Platforms Paradigms. Accepted for Annual SELinux Symposium.
|
| |
5
|
R. Anderson. Security in open versus closed systems-the dance of Boltzmann, Coase and Moore. In Open Source Software Economics 2002, 2002.
|
| |
6
|
S. Bajaj. Web services policy framework (wspolicy). March 2006, Version 1.2.
|
| |
7
|
R. Breu and G. Popp. Actor-centric modelling of access rights. In FASE 2004. Springer LNCS Vol. 2984, p. 165--179, 2004.
|
| |
8
|
D. Eastlake and J. Reagle. XML Encryption Syntax and Processing. W3C Rec. 10/12/2002.
|
| |
9
|
D. Eastlake and J. Reagle. XML-Signature Syntax and Processing. W3C Rec. 12/02/2002.
|
| |
10
|
D. Grawrock. The Intel Safer Computing Initiative Building Blocks for Trusted Computing. Intel Press, http://www.intel.com/intelpress/sum_secc.htm, 2005.
|
| |
11
|
M. Gudgin, M. Hadley, N. Mendelsohn, J. Moreau, and C. Nielsen. Soap version 1.2 part 1: Messaging framework. W3C Recommendation 24 June 2003.
|
| |
12
|
V. Haldar, D. Chandra, and M. Franz. Semantic remote attestation - a virtual machine directed approach to trustedcomputing.
|
| |
13
|
M. Hilty, A. Pretschner, C. Schaefer, and T. Walter. Enforcement for Usage Control: A System Model and a Policy Language for Distributed Usage Control. Technical Report I-ST-20, DoCoMo EuroLabs, 2006.
|
| |
14
|
|
 |
15
|
|
| |
16
|
|
| |
17
|
M. Hafner, M. Alam, R. Breu. A MOF/QVT-based Domain Architecture for Model Driven Security. In IEEE/ACM Models 2006 LNCS 4199.
|
| |
18
|
H. Maruyama, F. Seliger, N. Nagaratnam, T. Ebringer, S. Munetho, and S. Yoshihama. Trusted platform on demand. Technical report, IBM Research, 2006.
|
| |
19
|
OSGI Alliance. OSGi. The Dynamic Module System for Java. www.osgi.org.
|
 |
20
|
|
| |
21
|
|
 |
22
|
|
| |
23
|
A. Pretschner, F. Massacci, and M. Hilty. Usage Control in Service-Oriented Architectures. In Proc. TrustBus, 2007. To appear.
|
 |
24
|
|
 |
25
|
|
| |
26
|
Reiner Sailer , Xiaolan Zhang , Trent Jaeger , Leendert van Doorn, Design and implementation of a TCG-based integrity measurement architecture, Proceedings of the 13th conference on USENIX Security Symposium, p.16-16, August 09-13, 2004, San Diego, CA
|
| |
27
|
SAML 2.0 Specification. http://www.oasis-open.org/ committees/tc_home.php?wg_abbrev=security.
|
| |
28
|
Z. Song, S. Lee, and R. Masuoka. Trusted web service. In The Second Workshop on Advances in Trusted Computing (WATC '06 Fall), 2006.
|
| |
29
|
XACML 2.0 Specification Set. http://www.oasisopen. org/committees/tc_home.php?wg_abbrev=xacml.
|
| |
30
|
|
| |
31
|
X. Zhang, F. Parisi-Presicce, and R. Sandhu. Towards remote security enforcement for runtime protection of mobile code using trusted computing. In Proc. of the 1st Int. Workshop on Security (IWSEC), 2006. LNCS Kyoto, Japan.
|
CITED BY 2
|
|
Basel Katt , Xinwen Zhang , Ruth Breu , Michael Hafner , Jean-Pierre Seifert, A general obligation model and continuity: enhanced policy enforcement engine for usage control, Proceedings of the 13th ACM symposium on Access control models and technologies, June 11-13, 2008, Estes Park, CO, USA
|
|
|
Srijith K. Nair , Andrew S. Tanenbaum , Gabriela Gheorghe , Bruno Crispo, Enforcing DRM policies across applications, Proceedings of the 8th ACM workshop on Digital rights management, October 27-27, 2008, Alexandria, Virginia, USA
|
|