IEEE Transactions on Software Engineering · 2008 · 61 citations · 31 references
Ws-securityWeb Service SpecificationEngineeringService SecurityInformation SecurityVerificationService BehaviourSemantic WebSoftware AnalysisFormal VerificationSecurity ModellingFormal ModelingSecure By DesignComputer SciencePlan Services CompositionsSoftware DesignData SecurityCryptographySecure Web ServicesAutomated ReasoningProgram AnalysisFormal MethodsSecuritySecure MannerModel-driven Security
We outline a methodology for designing and composing services in a secure manner. In particular, we are concerned with safety properties of service behaviour. Services can enforce security policies locally and can invoke other services respecting given security contracts. This call-by-contract mechanism offers a significant set of opportunities, each driving secure ways to compose services. We discuss how to correctly plan services compositions in several relevant classes of services and security properties. To this aim, we propose a graphical modelling framework, based on a foundational calculus called lambda-req. Our formalism features dynamic and static semantics, so allowing for formal reasoning about systems. Static analysis and model checking techniques provide the designer with useful information to assess and fix possible vulnerabilities.
31
Web Services Business Process Execution Language Version 2.0
Charlton Barreto, Vaughn Bullard, Thomas Erl et al. · 2007 · 2.8K citations
Web Service Specification, Engineering, Web Service Modeling +3
Wil M. P. van der Aalst, Arthur H. M. ter Hofstede, Bartek Kiepuszewski et al. · Distributed and Parallel Databases · 2003 · 2.6K citations · Full text
Fred B. Schneider · ACM Transactions on Information and System Security · 2000 · 1.3K citations · Full text
M. Papazoglou, Dimitrios Georgakopoulos · Communications of the ACM · 2003 · 1.1K citations · Full text
Bibliometrics, Netherlands Tilburg University, Citation Analysis +5