A Synthetic Solution Scheme for SOA Security Assurance

Due to the changes of architecture, tradition security mechanism can’t fulfill SOA security requirements. So it is the high time to design a comprehensive security assurance system of models and solutions that fulfill SOA and SOA-based applications’ security requirement without hurting SOA’s loose coupling and high scalability features. Based on the in-depth research of tiered SOA security, this paper provides a comprehensive solution and analyzes SOA security assurance on three levels: strategy, service solution, testing. Firstly this paper proposes a new security assurance model for the overall architecture, and then proposes a new framework as a practical application solution for modeling and evaluating reliability on single service, service pool and service composition. At last, compared with traditional application-oriented system integration testing, this paper proposes the strategies of integration test and test responsibilities division for SOA systems. KeywordsSOA security assurance; reliability; service pool; integration test