ACM Home Page
Please provide us with feedback. Feedback
Secure web service federation management using tpm virtualisation
Full text PdfPdf (382 KB)
Source
Workshop On Secure Web Services archive
Proceedings of the 2007 ACM workshop on Secure web services table of contents
Fairfax, Virginia, USA
SESSION: Session 3 table of contents
Pages: 73 - 82  
Year of Publication: 2007
ISBN:978-1-59593-892-3
Authors
Srijith Krishnan Nair  Vrije Universiteit, Amsterdam, Netherlands
Ivan Djordjevic  British Telecommunications, Ipswich, United Kingdom
Bruno Crispo  Vrije Universiteit, Amsterdam, Netherlands
Theo Dimitrakos  British Telecommunications, Ipswich, United Kingdom
Sponsors
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
ACM: Association for Computing Machinery
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 11,   Downloads (12 Months): 131,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1314418.1314430
What is a DOI?

ABSTRACT

Web Services and SOA provide interoperability and architectural baseline for flexible and dynamic cross enterprise collaborations, where execution and use of the participating services contributes to the common objective. Relationships within these collaborations are complex, with services joining and leaving throughout the life cycle, or the same services being offered in several collaborations simultaneously. This provides strong requirements for federated security, where integrity and confidentiality of the collaboration must be maintained through membership control, security policy enforcement and separation of web service instance interactions in different collaborations.

In this paper we propose a new Web Services (WS) framework for managing and controlling WS interactions in a federated environment, leveraging on platform virtualisation architecture and the functionalities provided by trusted secure hardware. The framework allows configuring policies that define collaboration membership, and enforce access to the collaboration per-WS instance. In addition, since the access to the configurations is restricted, it provides masterslave model where only authorised administrative entity can modify any of the above - either at the deployment or at the execution time. Some of the benefits of the proposed approach are: fine-grained external exposure of WSs, a flexible model for group membership control and revocation and hardware-enabled secure virtualised system providing functional process isolation and strong data security.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
 
2
Djordjevic I., Dimitrakos T.: A system and protocol for coordinated management of shared security context of a collection of network entities within a federation. European Patent Office (in process, PCT application No. to be assigned)
 
3
"TCG Specification Architecture Overview", Trusted Computing Group, Revision 1.2, April 2004, https://www.trustedcomputinggroup.org/
 
4
Djordjevic I., Nair S.K., Dimitrakos T.: Virtualised Trusted Computing Platform for Adaptive Security Enforcement of Web Services Interactions. In proceedings of the International IEEE Conference on Web Services (ICWS07), July 9--13, 2007, Salt Lake City, Utah, USA
 
5
Sedhukin I. (editor) "Web Services Distributed Management: Management of Web Services (WSDMMOWS) 1.0". OASIS OASIS Web Services Distributed Management (WSDM) TC. Dec. 2004.
 
6
 
7
"TCG Generic Server Specification", v 1.0 revision 0.8, Trusted Computing Group, May 2005, https://www.trustedcomputinggroup.org/
 
8
Creasy R. J.: The Origin of the VM/370 Time-Sharing System, IBM Journal of Research and Development, 25(5):483, 1981.
 
9
 
10
Goldberg R. P.: Survey of Virtual Machine Research, IEEE Computer Magazine, 7(6):34--45, 1974.
 
11
Nanda S., Chiueh T.: A Survey of Virtualization Technologies, Research Proficiency Report, Stony Brook, ECSL-TR-179, February 2005.
 
12
 
13
Trusted Computing Group, https://www.trustedcomputinggroup.org/
 
14
 
15
Dimitrakos T.: Securing application service exposure & integration in B2B collaborations. In business track of ECOWS 2006, the 4th IEEE European Conference on Web Services, Zurich, December 2006.
 
16
TrustCoM project website: www.eu-trustcom.com
 
17
BEinGRID project website: www.beingrid.eu
 
18
 
19
Dondeti L.R., Mukherjee S., Samal A.: Survey and Comparison of Secure Group Communication Protocols. Technical Report, University of Nebraska-Lincoln, June 1999; http://citeseer.ist.psu.edu/dondeti99survey.html
20
 
21
 
22
 
23
Ateniese G., Steiner M., Tsudik G.: New Multiparty Authentication Services and Key Agreement Protocol. IEEE Journal on Selected Areas in Communications, Vol.18, No.4, April 2000; pp. 628--639
 
24
 
25
26
 
27
Pearlman L., Kesselman C., Welch V., Foster I., Tuecke S.: The Community Authorization Service: Status and Future. Conference for Computing in High Energy and Nuclear Physics (CHEP03), La Jolla, California, USA, March 2003.
 
28
Alfieri R. et al: Managing Dynamic User Communities in a Grid Autonomous Resources. Proc of Conference for Computing in High Energy and Nuclear Physics (CHEP03), La Jolla, California, USA, March 2003.
 
29
OASIS Specifications; http://www.oasis-open.org/committees/committees.php
 
30
Web Services Trust Specification, www.ibm.com/developerworks/library/specification/ws-trust/
 
31
Web Services Coordination Specification; www.ibm.com/developerworks/library/specification/ws-tx/
 
32
Web Service Definition Language (WSDL) Specification; http://www.w3.org/TR/wsdl
 
33
Web Services Resource Framework; http://www.globus.org/wsrf/
 
34
Djordjevic I.: Architecture for Dynamic and Secure Group Working. PhD Thesis, University of London, London, UK, June 2004

Collaborative Colleagues:
Srijith Krishnan Nair: colleagues
Ivan Djordjevic: colleagues
Bruno Crispo: colleagues
Theo Dimitrakos: colleagues