Ir directamente a la navegación principal Ir directamente a la búsqueda Ir directamente al contenido principal

From consumer requirements to policies in secure services

  • Erkuden Rios*
  • , Francesco Malmignati
  • , Eider Iturbe
  • , Michela D’Errico
  • , Mattia Salnitri
  • *Autor correspondiente de este trabajo

Producción científica: Contribución a una revistaArtículorevisión exhaustiva

Resumen

Automatic translation of elicited consumer security requirements at high level (problem space) into application or service level security requirements (solution space) has been traditionally the Achilles’ heel of security requirements engineering. Such automated translation would result in significant failure and cost reduction in application development and maintenance, particularly in those complex applications based on compositions and choreographies of services. In this paper we present a framework which makes a step forward to solve this dilemma. The framework supports the engineering of composite service security and trust requirements directly derived from the organisational needs expressed for such service. The followed approach starts with the modelling of organisation actors’ objectives and commitments among these actors, and follows with the transformation of such commitments into security elements in the service business process specification and into a consumer security policy which the service will need to be compliant with.

Idioma originalInglés
Páginas (desde-hasta)79-94
Número de páginas16
PublicaciónLecture Notes in Computer Science
Volumen8900
DOI
EstadoPublicada - 2014

Huella

Profundice en los temas de investigación de 'From consumer requirements to policies in secure services'. En conjunto forman una huella única.

Citar esto