portlet communication mechanism as defined in the
Java specification request (JSR) 286.
Future work of the authors is going to be per-
formed in a variety of fields, based on the work pre-
sented in this paper. First and foremost, the authors
are going to continue the work of thorough inves-
tigation of portal security aspects, predominantly in
the context of virtual enterprises and alliance-wide
application integration. A main cornerstone of fur-
ther research is the combination of different poli-
cies stemming from individual stakeholders, i.e. ser-
vice providers and consumers. Besides, the ques-
tion of runtime performance aspects of the encom-
passed solution is to be investigated in more detail.
Even though inter-portlet communication can only
seldomly be characterised as a time-critical function-
ality to the overall system, it is interesting to perform
deeper analysis on the scalability aspects of portlet
communication policies.
ACKNOWLEDGEMENTS
The research leading to these results is receiving fund-
ing from the European Community’s Seventh Frame-
work Programme under grant agreement no. 217098
and from the European Regional Development Funds
(ERDF). The content of this publication is the sole re-
sponsibility of the authors and in no way represents
the view of the European Commission or its services.
REFERENCES
AT&T Corp. (2008). Collaboration across borders.
http://www.corp.att.com/emea/docs/s5 collaboration
eng.pdf, retrieved 2010-02-26.
Beeson, B. and Wright, A. (2005). Developing reusable
portals for scripted scientific codes. In Proceedings of
the First International Conference on e-Science and
Grid Computing, pages 502–507. IEEE Computer So-
ciety.
Chadwick, D., Otenko, S., and Welch, V. (2005). Us-
ing SAML to link the GLOBUS toolkit to the PER-
MIS authorisation infrastructure. In Proceedings of
8th Annual IFIP TC-6 TC-11 Conference on Commu-
nications and Multimedia Security, pages 251–261.
Springer.
Hepper, S. (2008). JSR 286: Java Portlet Specification Ver-
sion 2.0. Java Community Process.
ISO/IEC (1996). ISO/IEC 10181-3:1996 Information tech-
nology – Open Systems Interconnection – Security
frameworks for open systems: Access control frame-
work. Technical report, ISO/IEC, New York, NY,
USA.
Katzy, B. R. (1998). Design and implementation of vir-
tual organizations. In Proceedings of the Thirty-First
Hawaii International Conference on System Sciences
(HICSS), volume 4, pages 142–151, Los Alamitos,
CA, USA. IEEE Computer Society.
Moreno, N., Romero, J. R., and Vallecillo, A. (2005). Incor-
porating cooperative portlets in web application de-
velopment. In Proceedings of the 1st Workshop on
Model-Driven Web Engineering (MDWE 2005), pages
70–79.
Moses, T. et al. (2005). eXtensible Access Control Markup
Language (XACML) Version 2.0. OASIS Standard.
Priebe, T. and Pernul, G. (2003). Towards integrative en-
terprise knowledge portals. In CIKM ’03: Proceed-
ings of the twelfth international conference on Infor-
mation and Knowledge management, pages 216–223,
New York, NY, USA. ACM Press.
Shilakes, C. C. and Tylman, J. (1998). Enterprise informa-
tion portals. Merril Lynch.
Song, J., Wei, J., and Wan, S. (2007). An HTML frag-
ments based approach for portlet interoperability. In
Distributed Applications and Interoperable Systems,
volume 4531/2007, pages 195–209. Springer Berlin /
Heidelberg.
Sun Microsystems, Inc. (2008). Sun Java System Portal
Server 7.2 Developer’s Guide. Sun Microsystems,
Inc., http://dlc.sun.com/pdf/820-2057/820-2057.pdf,
retrieved 2010-02-22.
Vullings, E., Dalziel, J., and Buchhorn, M. (2007). Secure
Federated Authentication and Authorisation to GRID
Portal Applications using SAML and XACML. In
Journal of Research and Practice in Information Tech-
nology, volume 39, pages 101–114. Australian Com-
puter Society Inc.
Westerinen, A., Schnizlein, J., Strassner, J., Scherling, M.,
Quinn, B., Herzog, S., Huynh, A., Carlson, M., Perry,
J., and Waldbusser, S. (2001). RFC3198: Terminol-
ogy for Policy-Based Management. Technical report,
IETF.
Yang, X. and Allan, R. (2006). Web-based Virtual Research
Environments (VRE): support collaboration in e-
Science. In Proceedings of the 2006 IEEE/WIC/ACM
international conference on Web Intelligence and In-
telligent Agent Technology, pages 184–187. IEEE
Computer Society Washington, DC, USA.
Yavatkar, R., Pendarakis, D., and Guerin, R. (2000).
RFC2753: A Framework for Policy-based Admission
Control. Technical report, IETF.
Yin, H., Zhou, J., Wu, H., and Yu, L. (2007). A SAM-
L/XACML Based Access Control between Portal and
Web Services. In Proceedings of the The First In-
ternational Symposium on Data, Privacy, and E-
Commerce, pages 356–360. IEEE Computer Society
Washington, DC, USA.
SECRYPT 2010 - International Conference on Security and Cryptography
182