Authors:
Wendpanga Francis Ouedraogo
1
;
Frederique Biennier
1
;
Catarina Ferreira Da Silva
2
and
Parisa Ghodous
2
Affiliations:
1
Université de Lyon, France
;
2
Université de Lyon and Université de Lyon 1, France
Keyword(s):
Context Aware Security, Execution Context, Security Patterns, Security Policy, Security as a Service.
Related
Ontology
Subjects/Areas/Topics:
Artificial Intelligence
;
Business Process Management
;
Cloud Computing
;
e-Business
;
Enterprise Engineering
;
Enterprise Information Systems
;
Knowledge Management and Information Sharing
;
Knowledge-Based Systems
;
Model-Driven Web Service Engineering
;
Services Science
;
Services Security and Reliability
;
Symbolic Systems
Abstract:
Taking advantage of the agility and interoperability provided by Service Oriented Architecture (SOA), Web 2.0
and XaaS (Anything as a Service) technologies, more and more collaborative Business Processes (BP) are set
”on demand” by selecting, composing and orchestrating different business services depending on the current
need. This involves re-thinking the way information, services and applications are organized, deployed, shared
and secured among multi-cloud environment. Fitting this de-perimeterized and evolving execution context
requires organising the service protection in a dynamic way in order to provide an up to date and consistent
protection. To fit this goal, we propose to integrate the different protection requirements defined according
to the business environment in a single security policy. Then we plug a context-aware security deployment
architecture on the cloud service middleware to analyse both the security policy and the execution context
to select, compose
and orchestrate the convenient protection means. A proof of concept built on Frascati
middleware is used to evaluate the impact of this ”on-line” security mediation.
(More)