0% found this document useful (0 votes)
5 views6 pages

Secure & Rapid Composition of Infrastructure Services in The Cloud

This paper proposes a novel infrastructure composition model. It aims at increasing the adaptability of the capabilities exposed through it by dynamically managing their non functional requirements. The virtual music store scenario will be presented as a use case.

Uploaded by

Kobana Kobe
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views6 pages

Secure & Rapid Composition of Infrastructure Services in The Cloud

This paper proposes a novel infrastructure composition model. It aims at increasing the adaptability of the capabilities exposed through it by dynamically managing their non functional requirements. The virtual music store scenario will be presented as a use case.

Uploaded by

Kobana Kobe
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

The Second International Conference on Sensor Technologies and Applications

Secure & Rapid composition of infrastructure services in the Cloud

Pierre de Leusse*, Panos Periorellis*, Paul Watson*, Andreas Maierhofer**


* School of Computing Science, Newcastle University
** Information Technology Futures Centre, British Telecommunications plc.
[Link]-leusse@[Link]

Abstract Service oriented computing and its proposed


methodology for designing services that are operating
A fundamental ambition of Grid and distributed as autonomously as possible, has also given rise to
systems is to be capable of sustaining evolution and alternative ways of thinking regarding application
allowing for adaptability [1, 2]. Furthermore, as the design and more importantly application delivery. S3
complexity and sophistication of theses structures [9] and EC2 [10] services that Amazon offers
increases, so does the need for adaptability of each demonstrate clearly the power of SOA from a
component. One of the primary benefits of Service developer’s point of view, but also highlight the power
Oriented Architecture (SOA) is the ability to compose gained by the end user, who can combine services on
applications, processes or more complex services from demand to create his custom browser based
other services which increases the capacity for application. The notion which is now becoming widely
adaptation. This document proposes a novel addressed as Cloud computing characterises such
infrastructure composition model that aims at flexible systems. In this paper we acknowledge the
increasing the adaptability of the capabilities exposed new trend of Cloud computing and we are bringing
through it by dynamically managing their non forward a new set of requirements –as our example
functional requirements. demonstrates- within which an execution environment
is created in which application services can offload non
1. Introduction functional requirements to contextualised on demand
services provisioned from the cloud. In our case, the
In the past few years, inter-application integration parameters governing the execution environment are
has become one of the main interests in the IT industry defined at context creation time, and can be adopted at
[2-5]. This has brought up the emerging growth of the any time in the execution process by authorised
Service Oriented Architecture (SOA) paradigm which entities. This approach has several advantages for both
has become the main reference in terms of distributed application providers and users.
software architectures [5]. Service orientation is a In a first part, the virtual music store scenario will
design paradigm intended for the creation of solution be presented as a use case. Following this, the
logic units that are individually shaped so that they can architecture of the intended solution will be introduced.
be collectively and repeatedly utilised in support of the Finally the current state of the work as well as its
realisation of a specific set of strategic goals and future will be discussed.
benefits associated with SOA and service-oriented
computing [6]. 2. Virtual music store Scenario
In such environments where change can be
frequent, adaptation to contextual changes is a strong 2.1. Description
requirement [7] but, due to its complexity, can be
difficult to achieve. Indeed, the SOA maturity model This section describes the virtual music store as an
described in [8] defines the ability to automatically example of a Virtualised Organisation (VO). VOs can
react and respond to change as one of the main be loosely defined as temporal collaborations between
characteristics of its top level environments. Such organisational entities [11]. According to [12], VOs are
changes can come from the need to adapt the non- frequently restructured, sustained to capture the value
functional behaviour (e.g. Security, QoS...) of a service of a market opportunity and dissolved again to give
according to different contexts. way for the creation of a next VO from within the

978-0-7695-3330-8/08 $25.00 © 2008 IEEE 777


770
DOI 10.1109/SENSORCOMM.2008.130
network of independent partners. This represents a This section describes the life-cycle of the virtual
need for adaptability that current systems, such as the music store. The music store life cycle starts with the
GOLD middleware [13] or the current B2B gateway initial agreements and discovery of the potential
[14, 15], attempt to address by providing one type of partners, the VO foundation. This is followed by the
security profile. negotiation between these partners and the VO initiator
The aggregated services are virtual music stores to reach a firm collaboration agreement, this stage is
serving specialised markets or communities of interest. called the partners’ federation. Following this, the
The basic service providers include copyright owners capabilities are virtualised and made available to the
of musical recordings or their representatives who partners in the newly formed VO. Finally the
make these recordings available online and syndicated adaptability faculty of the virtual store infrastructure is
blogs or review sites. The music stores reach introduced.
agreement with music providers enabling them to act
as re-sellers of bundles of recordings from their 2.3.1. VO foundation. Prior to any task and once the
catalogues. The virtual store is a VO consisting of the virtual shop has decided to establish the music store, it
music store operator as well as content providers and it needs to reach an agreement with the infrastructure
runs on top of an infrastructure provided by an provider. The infrastructure provider is said to provide
infrastructure provider. a VHE, on which it instantiates an ‘empty’ VO which
The end customer of the virtual music store will be is configured by the virtual shop operator.
a member of the public. What they will see is a normal The VHE being in place, the shop operator contacts
web-site where they will be able to search for and buy the potential participants of the music shop (i.e. content
tracks and read reviews and blogs. This could be providers). Agreements are reached between these
presented to them in much the same way as AbeBooks music providers and the shop operator and access to
does, i.e. a search page and then each returned item is the VO Manager is granted to the content providers to
linked in from an independent seller; or stores could setup their accounts and modify their data.
hide the aggregated nature of the service. The content providers can consequently publish the
business functions they want to expose. These selected
2.2. Partners and Roles capacities are published as services into a capability
registry.
In the music store, the main categories of partner
are: 2.3.2. Partner federation. At this stage it becomes
• Infrastructure provider possible for the virtual shop operator to put in place the
This role involves providing the VMS with a different services offered by the music store.
Virtual Hosting Environment (VHE), the B2B To achieve this, as introduced above, the operator
gateway. The purpose of the infrastructure is to hide creates a new VO for each federation of content
the technical complexity of the middleware involved to providers it wants to create. Additionally, the operator
the different participants in the virtual music store. defines a collaborative process to describe the
• Music content provider interactions between the different business functions
This is specialist content provider (eg. record labels potentially present in the federation. Once this
or other copyright owners). structure is in place, the operator can search the
• Virtual music store operator capability registry for the specific business functions it
The broker of music. It is assumed that the store wants to aggregate and using the VO Manager sends a
operator will be the VO Initiator. As such the operator participation request to the relevant providers.
is responsible for instigating the opening federation The providers contacted can inspect the process
process. description and interaction description already
• Value adding service provider provided by the store operator to take a decision upon
This is a third party entrusted with providing Value participating in this federation. Having accepted the
Adding Services (VAS). These services provide non invitation, the content providers associate to the VO
functional proprieties (eg. Security, audit, translation) the VAS profile they want to apply to this federation.
and allow the content providers and music store The VAS profiles are defined for each capability by its
operator to leverage on the VHE to enhance their provider.
interoperability and quality of service. These profiles include infrastructure services used
to secure and monitor the services. They are created
2.3. VO Lifecycle and managed in much the same way as the federation
between the operator and the music providers but
include the VAS providers. The services are typically

771
778
comprised of policy enforcement, authentication, Upon configuration of the infrastructure,
authorisation and other added value services such as provisioning of policy templates and establishment of
billing or auditing. In addition, the profiles are trust between the different VOs it becomes possible for
composed of policy templates that define the policies the capability instances exposed to be invoked within
to be applied to each of the selected infrastructure the context of the virtual music store.
services in the profile. 2.3.4. Adaptability. A music provider might want to
Following this, the operator can review and select participate in several such federations to increase its
the best matches in the positive answers it has visibility. But different partners in various VOs will
received. With all the targeted business functions have distinct security needs and settings. By adjusting
fulfilled, the virtual shop operator can continue the VO the VAS profile used in each federation to its specific
creation process and sends a creation order. needs, the content provider can more promptly offer its
The VO management tool subsequently interacts services.
with each partner’s gateway. To allow the different
identity providers to recognise each other’s authority, it 3. Architecture
sends the relevant list of business cards associated with
each business partner (role). In addition, the VO The infrastructure model presented in the following
management tool sends the policies related to the chapter is inspired by autonomous/adaptive computing
implementation of the collaboration management for architecture such as the Self-Managed Cell (SMC)
each business function. These policies come on the top presented in [16]. The objective of these architectures
of the security profiles setup and made available by the [17, 18] is to promote self-configuration, self-healing,
service providers. self-optimisation and self-protection. Although the
Brokered services, such as jazz music store model described below does not fully reach these
aggregating the different content providers’ services goals, mostly for security reason, its intention is to
that offer jazz music, can be created along with their provide adaptability for resources and therefore adopts
federation data following this method. the same ambition.

Figure 2. Secured Profile Management System

3.1. Negotiation Broker


Figure 1. The Jazz Music Store VO
The client broker is the interface that allows
2.3.3. Capability virtualization. With the federation
resource owners to define their requirements in term of
in place, it is possible for the participants to finalise the
the VASs added on the messages that come from or
configuration of the instances of the services they
towards their resources. The request consists of a list of
selected and prepared for this specific VO. Before
services required by the owner along with the
undertaking this, the gateway management interface
operation type the VAS profile is required for (e.g.
allows the participant to inspect the configuration of its
request or response). The request is expressed using an
infrastructure. At this stage, the configuration of the
ontology that is provided by the Profile Management
infrastructure will have evolved as the services are
system. It consists of a list of components with
exposed and activated. Additionally, the selected
potential constraints attached to them. These
Federated Identity Provider (FIP) has built trust with
constraints could include QoS (e.g. throughput, answer
the FIPs of the other partners in the VO. Furthermore,
time) details for the components used as well as
the baseline policies that restrict who can issue access
specific semantics to be used for certain operations
policies about which resources have been activated.
(e.g. XACML [19], SecPAL [20]).
Finally, the VAS profile that will be applied by the
Alternatively or additionally, the resource owners
Partner for the business functions it performs is stored
can declare adaptability level constraints. This could be
in a specific registry. To keep track of the
expressed in such a manner that all requests coming for
configuration, the settings are associated with a unique
certain partners in specific federations should be
collaboration ID.
accommodated as best as possible. Or at the opposite

772
779
that the choices made in terms of VASs required capabilities are selected and their compatibilities
should not be tempered with, or require the client’s checked. The system processes the AGCM, and for
authorisation to go further. each component described, attempts to find a
The second role of the Negotiation Broker is to capability or another AGCM that completely realises
allow other infrastructures such as the Profile it. This allows the creation the Abstract Specific
Management system to communicate and potentially Composition Model (ASCM) which is a location
negotiate terms of the VAS, in order to allow for specific version of the AGCM. This stage, along with
compatibility between the resource’s requester and the the previous one, corresponds to the planning sub-
resource’s interface as exposed for this particular cycle as defined by the ASG Semantic Enterprise
usage. Platform [21].
For instance, in the virtual music shop scenario With the ASCM completed, the concrete
described above, the virtual shop operator would send capabilities can now be searched and once found,
a participation request to a music provider. Upon its bound the Concrete Composition Model (CCM). This
reception, the content provider would check the discovery and selection could be made using non
collaborative process to see how its content would be functional properties. This stage corresponds to the
used and could decide to define a very open binding sub-cycle as defined by the ASG Platform
adaptability level, trusting the VO initiator in its [21]. This last stage results in the creation of a CCM
security choice. Alternatively, the music provider which, depending on the agreement can be proposed to
seeing that competitors could be able to access its the user.
pricing policy could require a specific VAS profile. Once the CCM has been validated, the required
capabilities can be instantiated; the Secured Profile
3.2. Client Registry (SP) can be deployed and made ready to be used. This
stage corresponds to the enactment sub-cycle as
The client registry holds data related to a particular defined by [21].
user. This data includes the different requests for VAS If the user doesn’t accept the proposed CCM,
Profile as well as adaptability level constraints, the another cycle is started with different requirements.
different composition models accepted, both abstract Note that in the future, the Predication Engine could
and concrete, as well as the degree of acceptance make different suggestions (CCMs) by itself based on
shown in front of potential alternatives proposed by the the knowledge of the user’s requirements and level of
Predication Engine. Finally, usage frequency, failure adaptability as well as the capabilities’ constraints.
rate and different critical data related to a particular
user and profile could also be held in this registry. 3.4. Architecture Descriptions Registry

3.3. Predication Engine In this registry the descriptions of the different


requirements and constraints for the allowed
The role of the predication engine is to determinate architectures are kept. These descriptions are expressed
the best possible way to achieve the VAS profile using the same formal model as the one applied to
requested. The decision making process is based on the validate the profile. The registry could be organised in
requirements given by the user, the capabilities held by categories with such architectures as Liberty Alliance
the system along with their associated constraints and in the Authentication category.
the architectural models stored in their registry.
In order to achieve this, the engine goes through a 3.5. Capability Registry
first stage that aims to create an Abstract Generic
Composition Model (AGCM). The AGCM validates The VAS registry allows the system to hold the
the user’s request against an ADM, this one being location, description and constraints related to the
given nominally by the user or assigned dynamically VAS. In addition to these traditional elements, the
by the system. During this stage, the VAS profile is Capability Registry will hold information about how to
being checked for completeness (e.g. missing set up the VAS. For instance, a Policy Decision Point
mandatory components) and the different VAS are (PDP) might need to build trust with a Security Token
being ordered. The AGCM is expressed using the same Service (STS) prior to any interaction. This process as
semantics as the request and defines the SP in terms of well as the VAS descriptions should be defined and
abstract components needed. expressed using the same ontology as the one used for
Once the closest component based AGCM possible the client’s request.
to the user requirements has been built, the matching

773
780
3.6. Secured Profile (SP) Factory As it is mentioned one of our aims is to alleviate
any constraints regarding message composition from
This component is divided in two different parts, the users. As such the method can be used to retrieve
the SP enactment engine and the message broker, such requirements from the users service interface.
together they allow for the VASs to be put in place. Such requirements can be expressed in an ad hoc
The enactment engine retrieves the relevant CCM from manner or make use of standards such as WS-Policy
the Client Registry at run time and implements the [22] and WS-Policy Attachment specifications [23]
appropriate SP. The message broker intercepts the that specify ways of expressing such requirements and
messages from and towards the resource, contacts the attaching them on WSDL interface descriptions. So
enactment engine and interacts with it before effectively, composition requirements of a message can
forwarding the message as appropriate. be expressed in a WS Policy document and attached by
reference to a WSDL description document. Although
3.7. Lifecycle Management WS Policy is an extensible standard we acknowledge
the difficulty in setting up semantics for a particular
Once the system has established that the Profile is domain. The fore mentioned WS-Policy Attachment
valid and recognised a way to enact it, it becomes specification provides a standard schema for
necessary to handle its lifecycle. This is achieved expressing security related requirements and a protocol
thanks to the agreement reached between the different for exchanging information to obtain such
partners (e.g. client, Infrastructure Provider…) on requirements.
service availability and potentially QoS. According to
this agreement, the VAS Profile can be made available
and managed in several different ways. First, the
profile is set up and exposed as soon as possible after
the request for it has been made and kept available as
often as possible. The second option is to set it up and
expose it only at specific times in conformity with the
agreement mentioned previously. Finally, the VAS
Profile is made available only when it is needed. These
are the three main options but variations between the
times the different stages of validations and enactment Figure 4. Dynamic profiling
are made are possible.
Internally, it is be possible for the secured gateway As figure 4 suggests end users can express their
to store the profile at different stages of validation or profile requirements in via some protocol which inform
enactment in the Client Registry to improve the interested parties of their preferences and consequently
performances of the process of VAS Profile enactment. trigger a profile creation at the recipient’s end. In the
above figure we suggest that by doing so we can
3.8. Adaptation enable security related profiles to be created on the fly
or on demand as services are discovered. A subset of
In a federated model such as the virtual music shop the available handlers is utilised in order to
scenario, the different partners must be able to accommodate or enable communication between 2
synchronise their common processes and semantics parties. Several profiles can be created depending on
(e.g. authentication and authentication protocols). The the type of user. Although it is not shown in the figure
initiator of the synchronisation would be the federation the profiling infrastructure can be independent of the
initiator or the member needing a change. In order to service itself alleviating the service from this extra
allow this, standardised interfaces will be available for workload.
the partners to communicate to each other. This will Furthermore, in addition to the actual adaptation
require the potential building of trust before the full strategy (e.g. modify access right), refinement of the
completion of the profile’s enactment. Alternatively profile and perhaps change of the profile’s architecture
customised forms are offered for participants to could be made in some cases (e.g. specific types of
express such requirements during the formation of the attacks might require different security architectures,
VO. The token is then sent by the requestor to the authentication mechanism…). This would have to be
resource owner for validation. Upon validation access made in accordance to the user’s adaptability level
to the resource is granted. constraints and potential validation.

774
781
4. Conclusions and future work [9] [Link]: Amazon S3, Amazon Simple Storage
Service, Unlimited Online Storage: Amazon Web Services.
[10] [Link]: Amazon EC2, Amazon Elastic Compute
In the paper we have introduced an infrastructure Cloud, Virtual Grid Computing: Amazon Web Services.
model that aims at increasing the adaptability and [11] BR Katzy, G.S., The Virtual Enterprise. Information
potentially the security of the resources exposed Age, 1995: p. 7.
through it. This is achieved by a mediator exposing a [12] Katzy, B.R. Design and implementation of virtual
virtualised interface of the resource enhanced with a organizations. in System Sciences, 1998., Proceedings of the
SP. The SP itself will be formed using semantic Thirty-First Hawaii International Conference on. 1998.
technologies linked with a formal model. The semantic [13] Periorellis, P., et al., GOLD Infrastructure for Virtual
technologies will describe the different components Organisations. UK e-Science All Hands Meeting, 2006: p.
along with their constraints and allow for their 11-20.
[14] Maierhofer, A., et al. Extendable and Adaptive
dynamic selection and composition. The formal model Message-Level Security Enforcement Framework. in
behind it will permit to insure the viability of the Networking and Services, 2006. ICNS '06. International
composition or SP as well as allowing improving it on conference on. 2006.
the fly. [15] Dimitrakos, T., et al. Contract performance assessment
The current state of this project is the BT Secured for secure and dynamic virtual collaborations. in Enterprise
B2B GW [14, 15]. It allows an enterprise to expose Distributed Object Computing Conference, 2003.
different capabilities as web services in a secure, Proceedings. Seventh IEEE International. 2003.
dynamic, and virtualised manner. The virtualisation is [16] Sventek, J., et al. Self-Managed Cells and their
guaranteed via the creation and management of service Federation. in 3rd Intl Conference on Mathematical
MethodSt Petersburg, Russias, Models and Architectures for
instances which contain infrastructure-specific Computer Networks Security (MMM-ACNS 2005). 2005.
configuration including security parameters. [17] Kephart, J. and D. Chess, The Vision of Autonomic
The next stage in this project is to define the Computing. Computer, 2003. 36(1): p. 41-50.
ontology describing the components as well as the [18] White, S., et al., Autonomic computing: Architectural
formal model [24]. We anticipate that the current state approach and prototype. Integr. Comput.-Aided Eng., 2006.
of the research in both domains will allow the quick 13(2): p. 173-188.
development of a working prototype. [19] Extensible Access Control Markup Language
There are a number of issues still to be resolved, (XACML).
such as making sure the communication protocols [20] Moritz, Y.B., D.G. Andrew, and C. Fournet, SecPAL:
Design and Semantics of a Decentralized Authorization
between the different B2B GWs or Secured Profile Language. September 2006.
Management System allow for smooth negotiations. [21] Noll, J. and E. Lillevold. Roadmap to ASG based
All the details of the different components and the way Semantic Web Services. in Telecommunications, 2006.
they communicate to each other are also still to be AICT-ICIW '06. International Conference on Internet and
concretely defined. Web Applications and Services/Advanced International
Conference on. 2006.
10. References [22] Bajaj, S., et al., Web Services Policy Framework
(WSPolicy). 2006.
[23] Bajaj, S., et al., Web Services Policy Attachment
[1] Losavio, F., D. Ortega, and M. Perez. Modeling EAI
(WSPolicyAttachment). 2006.
[Enterprise Application Integration]. in Computer Science
[24] Ter, A. Bucchiarone, and S. Gnesi. Web Service
Society, 2002. SCCC 2002. Proceedings. 22nd International
Composition Approaches: From Industrial Standards to
Conference of the Chilean. 2002.
Formal Methods. in Internet and Web Applications and
[2] Radhakrishnan, S., Integrating Entreprise Applications:
Services, 2007. ICIW '07. Second International Conference
Backgrounder. 2005.
on. 2007.
[3] de Leusse, P., P. Periorellis, and P. Watson, Enterprise
Service Bus: An overview, in Technical Reports, S.o.C.
Science, Editor. 2007, Newcastle University.
[4] Craggs, S., Raising EAI Standards. 2003.
[5] Natis, Y.V., et al., Predicts 2007: SOA Advances. 2006.
[6] Erl, T., Service-Oriented Architecture Concepts,
Technology, and Design. 2005.
[7] T. Dimitriakos, e.a., Towards a Trust and Contract
Management Framework for Dynamic Virtual Organisations.
eAdoption and the Knowledge Economy, 2004.
[8] Bachman, J., S. Kline, and B. Soni, A New Service-
Oriented Architecture Maturity Model. 2005.

775
782

You might also like