Security Assurance of Services through Digital Security Certificates

Samuel Paul Kaluvuri, Hristo Koshutanski, Francesco Di Cerbo, Antonio Maña · 2013

Service Oriented Computing (SOC) has facilitated a paradigm shift in software provisioning models: software gets consumed as a "service" providing enormous benefits, however lack of security assurance of third-party services is hampering their wider adoption in business- and security-critical domains. Security certification typically provides the required assurance, however applying it as is to SOC is infeasible, given that the natural language representation of resulting certificates is a major obstacle for typical SOC scenarios like service discovery, service composition and so on. To overcome the limitations of existing security certificates we present the concept of a digital security certificate for services. It is realized by a language which enables the representation of a security certificate in a structured, machine processable manner that would enable automated reasoning to be performed on them and thus make it feasible for certified security features to be part of typical SOC scenarios.

Read the paper · More papers on PaperTik