Web Service Composition Security Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current approaches to web services composition do not adequately integrate security requirements defined by designers, failing to consider security features as non-functional attributes during the composition process, which is crucial for ensuring the security of composite web services.

Innovation Solution

A method and system that automate the integration of security features by matching acceptable security features of a workflow model with those supported by candidate web services, using a modeling unit to define and advertise security features and an assignment unit to iteratively assign web services that satisfy the required security mechanisms, ensuring compliance with security requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security requirements are integrated as part of the composition procedure, then the security and reliability of composite web services is improved, but the complexity of the composition process increases

Engineering Contradiction:
Improvesecurity of composite web servicesVSAvoidcomposition process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by requiring workflow designers to specify security requirements and acceptable sets of security features during the workflow design phase, before the actual composition process begins. This allows security constraints to be pre-defined and automatically enforced during automated composition, improving security without significantly increasing composition complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary modeling layer that separates security requirements specification from the composition execution. The model acts as an intermediary between designer intent and automated composition, enabling security constraints to be systematically integrated without directly complicating the composition algorithm itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security features are considered as non-functional attributes during composition, then the security compliance of composite web services is improved, but the time required for composition increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidcomposition time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security requirements and acceptable security feature sets are specified in advance during workflow design, before composition begins. This preliminary specification allows the automated composition process to efficiently filter and select services that meet security criteria without time-consuming security analysis during composition execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated composition process self-evaluates candidate services against pre-defined security constraints and acceptable security feature sets. The system autonomously filters services based on security attributes without requiring manual security verification, maintaining both security compliance and composition efficiency.

Inventive Principle:
Principle #25Self-service

3Manufacturing precision

If matching procedures are used to align security features of workflow models with candidate web services, then the accuracy of security requirement satisfaction is improved, but the complexity of the composition system increases

Engineering Contradiction:
Improvesecurity requirement satisfaction accuracyVSAvoidcomposition system complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent introduces a modeling intermediary that provides structured representations of security requirements and service security features. This modeling layer enables systematic matching between workflow security needs and candidate service capabilities without requiring complex custom matching logic, thereby improving matching accuracy while controlling system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security feature model serves multiple functions: it specifies security requirements, defines acceptable security features, enables service filtering, and supports automated matching. This multi-functional modeling approach improves security requirement satisfaction accuracy without proportionally increasing system complexity by reusing the same modeling infrastructure for multiple purposes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2164226B1Secure composition of web services
Publication Date: 2010.05.19 SAP SE
  • EP2164226B1 patent drawingFigure 1~2
  • EP2164226B1 patent drawingFigure 3~4
  • EP2164226B1 patent drawingFigure 5

AI summary

A method for automating an integration of security features as part of a composition procedure of web services, the method comprising providing a model which allows to define acceptable sets of security features ((sfk(W))k ∈ [1,1]) associated with a particular workflow model (W) representing a composite web service (C), and to enable to advertise security features (SMS(si)) which are supported by available candidate web services (si), and defining, based on the model, an assignment procedure which allows to build, based on the available candidate web services, a secure compliant composite web service which satisfies at least one of the acceptable sets of security features ((sfj(W))j ∈ [1,1]) of the workflow model, wherein the assignment procedure is an iterative process in that web services are assigned to workflow tasks one after the other such that after each iteration a subset of the at least one acceptable set of security features which is supported by the web services already assigned is analyzed in view of the next succeeding workflow task of the workflow model so as to be successively completed to the at least one acceptable set of security features by compliant candidate web services. An appropriate system and an appropriate computer program product are also provided.