arrow
Return

Semantics-based design for secure web services

delete2008-01-01
delete40
PRE
AI
M
Massimo Bartoletti *
P
Pierpaolo Degano
G
Gian-Luigi Ferrari
R
Roberto Zunino
DOI:10.1109/TSE.2007.70740delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
We outline a methodology for designing and composing services in a secure manner. In particular, we are concerned with safety properties of service behavior. Services can enforce security policies locally and can invoke other services that respect given security contracts. This call-by-contract mechanism offers a significant set of opportunities, each driving secure ways to compose services. We discuss how we can correctly plan service compositions in several relevant classes of services and security properties. With this aim, we propose a graphical modeling framework based on a foundational calculus called lambda(req) [13]. Our formalism features dynamic and static semantics, thus allowing for formal reasoning about systems. Static analysis and model checking techniques provide the designer with useful information to assess and fix possible vulnerabilities.
Keywords:
web services
call-by-contract
language-based security
static analysis
system verification

Journal

IEEE Transactions on Software Engineering cover
IEEE Transactions on Software Engineering
IF:
5.6
Papers:
2.8K
Citations:
1.1W

Organization

U
University of Pisa
Scholars:
3.1W
Papers: 2.4W
Citations: 2.4W