Security Assurance of Services through Digital Security Certificates
Samuel Paul Kaluvuri, Hristo Koshutanski, Francesco Di Cerbo, Antonio Maña · 2013
Service Oriented Computing (SOC) has facilitated a paradigm shift in software provisioning models: software gets consumed as a "service" providing enormous benefits, however lack of security assurance of third-party services is hampering their wider adoption in business- and security-critical domains. Security certification typically provides the required assurance, however applying it as is to SOC is infeasible, given that the natural language representation of resulting certificates is a major obstacle for typical SOC scenarios like service discovery, service composition and so on. To overcome the limitations of existing security certificates we present the concept of a digital security certificate for services. It is realized by a language which enables the representation of a security certificate in a structured, machine processable manner that would enable automated reasoning to be performed on them and thus make it feasible for certified security features to be part of typical SOC scenarios.