Dynamic Authentication for Cross-Realm SOA-Based Business Processes

Dynamic Authentication for Cross-Realm SOA-Based Business Processes
复制标题

DOI:
10.1109/tsc.2010.33
复制
发表时间:
2012
影响因子:
8.1
通讯作者:
Jie Xu;Dacheng Zhang;Lu Liu;Xianxian Li
Jie Xu;Dacheng Zhang;Lu Liu;Xianxian Li
中科院分区:
计算机科学2区
文献类型:
--
作者:
Jie Xu;Dacheng Zhang;Lu Liu;Xianxian Li

文献摘要

被引文献

相似文献

现代分布式应用程序嵌入了越来越多的动态性,从动态供应链管理、企业联盟和虚拟协作到跨组织的动态资源获取和服务交互。这种活力导致安全和可靠性方面的新挑战。在具有面向服务的体系结构(SOA)的系统中,协作服务可能属于不同的安全领域,但通常需要在运行时动态参与。如果它们的安全领域没有直接的跨领域身份验证关系,那么在技术上很难在服务之间启用任何安全协作。一个潜在的解决方案是在运行时定位中间领域,它充当两个独立领域之间的身份验证路径。然而,为两个分布式服务生成认证路径的过程可能非常复杂。它可能涉及大量额外的凭证转换操作,并需要对中间服务的长链调用。在本文中,我们解决这个问题,设计和实现一个新的跨领域的动态服务交互的认证协议,面向服务的多方业务会话的概念的基础上。我们的协议既不需要证书转换,也不需要在业务会话中的参与服务之间建立任何认证路径。该协议的正确性进行了形式化的分析和证明,并进行了实证研究,使用两个生产质量的网格系统,Globus 4和皇冠。实验结果表明,所提出的协议及其实现具有良好的可扩展性,并施加只有有限程度的性能开销,这是例如与Globus 4中的安全相关的开销相媲美。
Modern distributed applications are embedding an increasing degree of dynamism, from dynamic supply-chain management, enterprise federations, and virtual collaborations to dynamic resource acquisitions and service interactions across organizations. Such dynamism leads to new challenges in security and dependability. Collaborating services in a system with a Service-Oriented Architecture (SOA) may belong to different security realms but often need to be engaged dynamically at runtime. If their security realms do not have a direct cross-realm authentication relationship, it is technically difficult to enable any secure collaboration between the services. A potential solution to this would be to locate intermediate realms at runtime, which serve as an authentication path between the two separate realms. However, the process of generating an authentication path for two distributed services can be highly complicated. It could involve a large number of extra operations for credential conversion and require a long chain of invocations to intermediate services. In this paper, we address this problem by designing and implementing a new cross-realm authentication protocol for dynamic service interactions, based on the notion of service-oriented multiparty business sessions. Our protocol requires neither credential conversion nor establishment of any authentication path between the participating services in a business session. The correctness of the protocol is formally analyzed and proven, and an empirical study is performed using two production-quality Grid systems, Globus 4 and CROWN. The experimental results indicate that the proposed protocol and its implementation have a sound level of scalability and impose only a limited degree of performance overhead, which is for example comparable with those security-related overheads in Globus 4.