Towards Deciding Policy Violation During Service Discovery

Towards Deciding Policy Violation During Service Discovery
复制标题

在服务发现期间决定策略违规

DOI:
--
复制
发表时间:
2011
期刊:
Central-European Workshop on Services and their Composition
影响因子:
--
通讯作者:
Jan Sürmeli
Jan Sürmeli
中科院分区:
--
文献类型:
--
作者:
Jan Sürmeli

文献摘要

被引文献

相似文献

在面向服务的体系结构中,提供者在服务存储库中发布其服务。请求者接近代理,代理返回与请求者的服务R匹配的服务S,然后,S和R耦合。S的提供者可能需要执行S的费用和奖励之间的特定关系,总结在策略φ中。S的控制流可能同时包含内部和外部决策:通过发送消息,R可能触发某个执行路径。基于S和R的模型,代理可以在耦合之前判断R是否违反φ。在本文中,我们提供了一个正式的框架来建模策略,并引入了一个基于服务的开放网络模型的策略违反决策过程。我们将服务理解为具有内部控制流和与其他服务异步交换消息的接口的组件。因此,它提供了可能被其他服务使用的某些功能。提供者在存储库中发布其服务。请求者通过代理访问先前发布的服务。提供者因提供服务而获得奖励。这个奖励可以表现为使用费,或者来自存储库所有者的规定,或者来自任何第三方。通常,提供者希望这种报酬与提供其服务的费用之间存在某种有益的关系。例如,提供者可能希望用奖励来支付费用。我们将这些需求指定为策略。合伙人要么违反政策,要么不违反政策。提供商的目标是其服务仅与非违规合作伙伴耦合。奖励和费用都可能有固定和可变的组成部分。这是经济学中一个很常见的问题,解决这个问题的方法早就知道了。然而,在我们的例子中,我们遇到了另一个困难:我们考虑有状态服务。有状态服务有自己的控制流,控制流受内部和外部决策的影响。外部决策是通过异步消息交换做出的。因此,提供服务的报酬和费用因请求者而异。作为一个运行的例子,考虑一个出售咖啡和茶的自动售货机,在图1(a)中建模为一个开放的网络[1]。在初始状态下,它等待以下三条消息中的一条:咖啡订单、茶订单或退出消息。为了接收订单,它执行相应的转换c或t。随后,它通过执行b来提供饮料。执行q可能会消耗退出消息,从而导致最终状态ω。这台机器最多可以提供三种饮料,由底部的三个代币表示。自动售货机的提供者提供服务的固定费用可能是10单位,所提供的每种饮料的可变费用取决于类型:咖啡20单位,茶10单位。作为奖励,供应商收取固定数量的5个单位和额外的25个单位的饮料。假设供应商希望费用完全由φV政策中规定的奖励支付。我们发现,至少点一种饮料的顾客是好顾客,而不点饮料、干脆不喝的顾客就不是好顾客。然而,异步消息交换引发了一个微妙的问题:在收到饮料之前订购饮料然后发送退出消息的客户是一个坏客户:自动售货机可能首先收到退出消息。图1(b)显示了V的一个简单伙伴:D点了一杯茶或咖啡,接受了饮料,并发送了一条退出消息。显然,D不违反φV。
In a service-oriented architecture, a provider publishes its service in a service repository. A requester approaches a broker which returns a service S matching the requester’s service R. Then, S and R are coupled. The provider of S may require a specific relation between the expenses and rewards for an execution of S, summarized in a policy φ. The control flow of S may contain both internal and external decisions: By sending messages, R may trigger a certain execution path. Based on models of S and R, the broker may decide if R violates φ before coupling. If so, the broker may not couple S and R. In this paper, we provide a formal framework to model policies, and introduce a decision procedure for policy violation based on open net models of the services. 1 Setting and problem We understand a service as a component with an inner control flow and an interface to exchange messages asynchronously with other services. Thereby, it provides a certain functionality which may be used by other services. A provider publishes its service in a repository. A requester approaches a broker for accessing a previously published service. The provider earns a reward for providing its service. This reward may manifest as a usage fee, or a provision from the repository owner, or from any third party. Usually, a provider desires some beneficial relation between this reward and the expenses for providing its service. As an example, a provider might want the expenses to be covered by the reward. We specify such requirements as policies. A partner either violates a policy or not. The provider aims at its service being coupled only with non-violating partners. Both reward and expenses may have fixed and variable components. This is a quite usual problem in economics and solutions for this problem are known for a long time. However, in our case, we encounter another difficulty: We consider stateful services. A stateful service has its own control flow which is influenced by internal and external decisions. External decisions are made through asynchronous message exchange. Therefore, reward and expenses for providing a service vary from requester to requester. As a running example, consider a vending machine which sells coffee and tea, modeled as an open net [1] in Fig. 1(a). In its initial state, it waits for one of three messages: Either an order for coffee, an order for tea, or a quit message. To receive an order it executes the respective transition c or t. Subsequently, it serves the beverage by executing b. A quit message may be consumed by executing q, resulting in a final state ω. The machine may serve up to three beverages, as indicated by the three tokens in the place in the bottom. The provider of the vending machine may have fixed expenses of 10 units for providing its service and variable expenses for each served beverage depending on the type: 20 units for coffee and 10 units for tea. As a reward, the provider collects a fixed amount of 5 units and additionally 25 units per served beverage. Assume the provider desires the expenses to be fully covered by the reward, specified in a policy φV. We find that a customer ordering at least one beverage is a good customer, whereas a customer ordering nothing and simply quitting is not. However, asynchronous message exchange induces a subtle problem: A customer ordering a beverage and then sending the quit message before receiving the beverage is a bad customer: The vending machine might receive the quit message first. A simple partner for V is shown in Fig. 1(b): D orders either a tea or a coffee, receives the beverage, and sends a quit message. Obviously, D does not violate φV.