Information Flow Analysis Based Security Checking of Health Service Composition Plans
Dieter Hutter, Matthias Klusch, Melanie Volkamer · Repository KITopen (Karlsruhe Institute of Technology) · 2006
Abstract: In this paper, we present anapproach to solve the problem of provably secure execution of semantic web service composition plans. The integrated components of this approach include our OWL-S service matchmaker, OWLS-MX, the service composition planner, OWLS-XPlan, and the security checker module for formally verifying the compliance of the created composition plan to be executed with given data and service security policies using type-based information flow analysis. We demonstrate this approach by means of its application to ause casescenario ofhealth servicecomposition planning. 1Introduction The composition of complex services available in the Web, and the semantic Web, at design time isawell-understood principle which is nowadays supported by, for example, service composition planners such as SHOP2, or OWLS-XPlan. However, ensuring the secure execution of composed services still remains tobeachallenge. Related tasks range from secure communication via protection of services against misuse to the preservation ofuser data privacy. Standard approaches for secure execution ofservices