loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
International Conference on Software Engineering Advances (ICSEA'06)
SOA-Aware Authorization Control
Tahiti, French Polynesia
October 29-November 03
ISBN: 0-7695-2703-5
Christian Emig, Universitat Karlsruhe (TH), Germany
Heiko Schandua, Universitat Karlsruhe (TH), Germany
Sebastian Abeck, Universitat Karlsruhe (TH), Germany
The question how to handle authorization of digital identities in a service-oriented architecture (SOA) remains an open issue. In this paper we present a design pattern for the integration of legacy systems with SOA using out-of-the-box (unmodified) application servers and discuss how the architecture has to be extended by an Identity Management (IdM) infrastructure. We claim that the IdM infrastructure itself must be designed in a service-oriented way to fit into the overall SOA approach. We introduce a possibility how to decouple the policy enforcement point from the application server and propose an architectural design pattern to seamlessly integrate the SOA?s business-related functionality and the IdM infrastructure. An implementation case study illustrates how to apply the invocation pattern for secured web services.
Citation:
Christian Emig, Heiko Schandua, Sebastian Abeck, "SOA-Aware Authorization Control," icsea, pp.62, International Conference on Software Engineering Advances (ICSEA'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.