scholarly journals Trusted Enforcement of Application-specific Security Policies

Author(s):  
Marius Schlegel
2008 ◽  
pp. 206-227
Author(s):  
Konstantin Beznosov

This chapter reports on our experience of designing and implementing an architecture for protecting enterprise-grade Web service applications hosted by ASP.NET. Security mechanisms of Microsoft ASP.NET container—a popular hosting environment for Web services—have limited scalability, flexibility, and extensibility. They are therefore inade-quate for hosting enterprise-scale applications that need to be protected according to diverse and/or complex application-specific security policies. To overcome the limitations of ASP.NET security, we developed a flexible and extensible protection architecture. Deployed in a real-world security solution at a financial organization, the architecture enables integra-tion of ASP.NET into the organizational security infrastructure with reduced effort on the part of Web Service developers. Throughout this report, we discuss our design decisions, suggest best practices for constructing flexible and extensible authentication and authoriza-tion logic for Web Services, and share lessons learned.


2012 ◽  
Vol E95-C (4) ◽  
pp. 534-545 ◽  
Author(s):  
Wei ZHONG ◽  
Takeshi YOSHIMURA ◽  
Bei YU ◽  
Song CHEN ◽  
Sheqin DONG ◽  
...  

2005 ◽  
Author(s):  
Andrew W. Appel ◽  
Edward W. Felton ◽  
David P. Walker ◽  
Zhong Shao ◽  
Valery Trifonov
Keyword(s):  

Sign in / Sign up

Export Citation Format

Share Document