Towards Security Certification Schemas for the Internet of Services
Volkmar Lotz, Samuel Paul Kaluvuri, Francesco Di Cerbo, Antonino Sabetta · 2012
The Internet of Services (IoS) has become the dominant paradigm for building applications in an ad-hoc, dynamic fashion by composing services from a variety of different providers. While the business value of the IoS is undoubted, security and trustworthiness concerns still constitute an obstacle for uptake. In this paper we argue that security certification is a valid means to address these issues. However, existing certification schemes addressing static systems and environments do not scale to the IoS and, thus, cannot be straightforwardly adapted. We investigate into the reasons for the lack of scale and conclude that three areas need to be addressed: explicit representation, machine readability, and advanced composition support. For each of these areas, we sketch solutions and identify further challenges.