Security Services Lifecycle Management in Dynamically Provisioned Composable Services GEMBus Infrastructure for Composable Services ITU-T standards seria.

Slides:



Advertisements
Similar presentations
Large-Scale, Adaptive Fabric Configuration for Grid Computing Peter Toft HP Labs, Bristol June 2003 (v1.03) Localised for UK English.
Advertisements

What Does it Mean to be a Strategic NESSI Project?
DOPSYgroup Distributed Systems Lab Wiesbaden University of Applied Sciences Self-Organizing QoS-Management in Service Oriented Architectures.
Tom Sugden EPCC OGSA-DAI Future Directions OGSA-DAI User's Forum GridWorld 2006, Washington DC 14 September 2006.
Sensor Web Enablement and GEOSS Presented by: Terence van Zyl.
All rights reserved © 2006, Alcatel Grid Standardization & ETSI (May 2006) B. Berde, Alcatel R & I.
1 Introducing the Specifications of the Metro Ethernet Forum.
1 Introducing the Specifications of the Metro Ethernet Forum.
1 Introducing the Specifications of the Metro Ethernet Forum.
Presented to: By: Date: Federal Aviation Administration Registry/Repository in a SOA Environment SOA Brown Bag #5 SWIM Team March 9, 2011.
The DRIVER Infrastructure (Digital Repository Infrastructure Vision for European Research) Paolo Manghi ISTI - National Research Council, Italy.
1 Building scientific Virtual Research Environments in D4Science Paul Polydoras University of Athens, Greece.
Geneva, Switzerland, 17 October 2011 ITU Workshop on Service Delivery Platforms (SDP) for Telecommunication Ecosystems: from todays realities to requirements.
Geneva, 15 May 2009 Status of NGN architecture related studies in ITU-T SG13 Olivier Le Grand WP 3/13 chairman France Telecom JOINT ITU-T SG13 - IEEE NGSON.
The e-Framework Bill Olivier Director Development, Systems and Technology JISC.
Current status of grids: the need for standards Mike Mineter TOE-NeSC, Edinburgh.
Hello i am so and so, title/role and a little background on myself (i.e. former microsoft employee or anything interesting) set context for what going.
Welcome to Middleware Joseph Amrithraj
Multi-level SLA Management for Service-Oriented Infrastructures Wolfgang Theilmann, Ramin Yahyapour, Joe Butler, Patrik Spiess consortium / SAP.
Policy based Cloud Services on a VCL platform Karuna P Joshi, Yelena Yesha, Tim Finin, Anupam Joshi University of Maryland, Baltimore County.
THE CORE PROJECT Jose Jimenez (project manager). What is the Core platform?
Component-Based Software Engineering Main issues: assemble systems out of (reusable) components compatibility of components.
IONA Technologies Position Paper Constraints and Capabilities for Web Services
Jose Jimenez Director. International Programmes Telefónica Digital.
Integrating SSA&I projects into the Future Internet activities Limitations of the current Internet.
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All Wayne Zeuch, ATIS ATIS Cybersecurity Standards Document No: GSC16-GTSC9-10 Source: ATIS Contact:
©Ian Sommerville 2006Software Engineering, 8th edition. Chapter 31 Slide 1 Service-centric Software Engineering 1.
Connect communicate collaborate A Network Management Architecture proposal for the GEANT-NREN environment Pavle Vuletić, Afrodite Sevasti TNC 2010, ,
1 OOI Cyberinfrastructure Overview of the Governance Architecture 09 Jan 2014.
A Java Architecture for the Internet of Things Noel Poore, Architect Pete St. Pierre, Product Manager Java Platform Group, Internet of Things September.
Asper School of Business University of Manitoba Systems Analysis & Design Instructor: Bob Travica System architectures Updated: November 2014.
Community Manager A Dynamic Collaboration Solution on Heterogeneous Environment Hyeonsook Kim  2006 CUS. All rights reserved.
Security Services Lifecycle Management and GEYSERS Service Delivery Framework Yuri Demchenko, UvA Cloud Security BOF 26 October 2010 OGF October.
SOA – Development Organization Yogish Pai. 2 IT organization are structured to meet the business needs LOB-IT Aligned to a particular business unit for.
DESIGN OF A PLATFORM OF VIRTUAL SERVICE CONTAINERS FOR SERVICE ORIENTED CLOUD COMPUTING Carlos de Alfonso Andrés García Vicente Hernández.
THE NEXT STEP IN WEB SERVICES By Francisco Curbera,… Memtimin MAHMUT 2012.
© Drexel University Software Engineering Research Group (SERG) 1 Based on the paper by Philippe Kruchten from Rational Software.
 Cloud computing  Workflow  Workflow lifecycle  Workflow design  Workflow tools : xcp, eucalyptus, open nebula.
1 Multi Cloud Navid Pustchi April 25, 2014 World-Leading Research with Real-World Impact!
Climate Sciences: Use Case and Vision Summary Philip Kershaw CEDA, RAL Space, STFC.
Ocean Observatories Initiative Common Execution Infrastructure (CEI) Overview Michael Meisinger September 29, 2009.
M.A.Doman Short video intro Model for enabling the delivery of computing as a SERVICE.
ASG - Towards the Adaptive Semantic Services Enterprise Harald Meyer WWW Service Composition with Semantic Web Services
Architecting Web Services Unit – II – PART - III.
Web Services Based on SOA: Concepts, Technology, Design by Thomas Erl MIS 181.9: Service Oriented Architecture 2 nd Semester,
Service Oriented Architectures Presentation By: Clifton Sweeney November 3 rd 2008.
Middleware for FIs Apeego House 4B, Tardeo Rd. Mumbai Tel: Fax:
1 Advanced Software Architecture Muhammad Bilal Bashir PhD Scholar (Computer Science) Mohammad Ali Jinnah University.
NA-MIC National Alliance for Medical Image Computing UCSD: Engineering Core 2 Portal and Grid Infrastructure.
Connect communicate collaborate The GEMBus Way Delivering the Promise of the Internet of Services Diego R. Lopez, RedIRIS.
Distribution and components. 2 What is the problem? Enterprise computing is Large scale & complex: It supports large scale and complex organisations Spanning.
Jose Jimenez Telefónica I+D Future Network & Mobile Summit 2011 The vision of Future Internet in the FI PPP Core Platform project.
The FI-WARE Project – Base Platform for Future Service Infrastructures FI-WARE Stefano De Panfilis (Fi-WARE PCC Member) 4 th July 2011 FInES - Samos Summit.
The concepts of Generic AAA are described in RFC2903 [1] (Generice AAA Architecture) and RFC2904 [2] (Authorization Framework). Several.
Diego R. Lopez, RedIRIS JRES2005, Marseille On eduGAIN and the Coming GÉANT Middleware Infrastructure.
DICE: Authorizing Dynamic Networks for VOs Jeff W. Boote Senior Network Software Engineer, Internet2 Cándido Rodríguez Montes RedIRIS TNC2009 Malaga, Spain.
INFSO-RI JRA2 Test Management Tools Eva Takacs (4D SOFT) ETICS 2 Final Review Brussels - 11 May 2010.
Context-Aware Middleware for Resource Management in the Wireless Internet US Lab 신현정.
Issues in Cloud Computing. Agenda Issues in Inter-cloud, environments  QoS, Monitoirng Load balancing  Dynamic configuration  Resource optimization.
Service Oriented Architecture (SOA) Prof. Wenwen Li School of Geographical Sciences and Urban Planning 5644 Coor Hall
CLOUD ARCHITECTURE Many organizations and researchers have defined the architecture for cloud computing. Basically the whole system can be divided into.
Bob Jones EGEE Technical Director
GENUS Virtualisation Service for GÉANT and European NRENs
Architecting Web Services
The GEMBus Architecture and Core Components
Federated IdM Across Heterogeneous Clouding Environment
Architecting Web Services
Service Oriented Architecture (SOA)
Introduction to SOA Part II: SOA in the enterprise
Presentation transcript:

Security Services Lifecycle Management in Dynamically Provisioned Composable Services GEMBus Infrastructure for Composable Services ITU-T standards seria Y: Global information infrastructure, Internet protocol aspects and Next-Generation Networks (NGN) ITU-T REC Y.2232 (01/2008) NGN convergence service model and scenario using Web Services ITU-T REC Y.2234 (09/2008) Open service environment capabilities for NGN ITU-T REC Y.2701 (04/2007) Security requirements for NGN release 1 Security requirements to NGN and security services binding to basic NGN interfaces (e.g., UNI, NNI, ANI) TMF standardised frameworks, practices and procedures NGOSS – New Generation Operations Systems and Software (including eTOM) SDF - Service Delivery Framework SLAM - Service Level Agreement (SLA) Management Framework Open Group Service Integration Maturity Model (OSIMM) Provides framework for evaluation and development of the strategy for business model/processes migration to true SOA Defines 7 maturity level and 7 dimensions to achieve Dynamically reconfigured virtualised services To ensure consistency security issues addressed at multiple dimensions: Business, Methods/models, Services. (Information) Microsoft Security Development Lifecycle (SDL) Framework Primarily focused on the product development process by engineers/programmers (Training) – Requirements – Design – Implementation – Verification – Release – (Response) 1.Service instance 2.Service Management Interface 3.Service Functional Interface 4.Management Support Service (SDF MSS) 4.Infrastructure Support Service (ISS) Security Service request and generation of the GRI that will serve as a provisioning session identifier and will bind all other stages and related security context. Reservation session binding that provides support for complex reservation process including required access control and policy enforcement. Deployment stage begins after all component resources have been reserved and includes distribution of the security context and binding the reserved resources or services to GRI as a common provisioning session ID. Registration&Synchronisation stage (optional) specifically targets possible scenarios with the provisioned services migration or failover/interruption. In a simple case, the Registration stage binds the local resource or hosting platform run-time process ID to the GRI as a provisioning session ID. Operation stage - security services provide access control to the provisioned services and maintain the service access or usage session. Decommissioning stage ensures that all sessions are terminated, data are cleaned up and session security context is recycled. SLM stages RequestDesign/ Reservation Development DeploymentOperationDecomissi oning Process/ Activity SLA Nego tiation Service/ Resource Composition Reservation Composition Configuration Orchestratio n/ Session Managemen t Logoff Accountin g Mechanisms/Methods SLA VV Workflow (V)V Metadat a VVVV Dynamic Security Associat n (V)VV AuthZ Session Context V(V)V Logging (V) VV Components of the typical e-Science infrastructure involving multidomain and multi-tier Grid and Cloud resources and network infrastructure. Security Services Lifecycle Model Credits: Yuri Demchenko, Cees de Laat, Diego R. Lopez, Joan A. Garcia Espin Contact: Yuri Demchenko Service Delivery Framework (SDF) by TeleManagement Forum (refactored from[1]) Targeted automation of the whole service delivery and operation process including: End-to-end service management in a multi- service providers environment End-to-end service management in a composite, hosted and/or syndicated service environment Management functions to support a highly distributed service environment, for example unified or federated security, user profile management, charging etc. Any other scenario that pertains to a given phase of the service lifecycle challenges, such as on-boarding, provisioning, or service creation Use case: Provisioning Multi-domain Collaborative Environment On-Demand Existing Frameworks in Services Virtualisation and On-Demand Provisioning Composable Services Architecture (CSA) General and security mechanisms in SLM/SSLM SLA – used at the stage of the service Request placing and can also include SLA negotiation process. Workflow is typically used at the Operation stage as service Orchestration mechanism and can be originated from the design/reservation stage. Metadata are created and used during the whole service lifecycle and together with security services actually ensure the integrity of the SLM/SSLM. Dynamic Security Associations support the integrity of the provisioned resources and are bound to the security sessions. Authorisation Session Context supports integrity of the authorisation sessions during Reservation, Deployment and Operation stages. Logging can be actually used at each stage and essentially important during the last 2 stages – Operation and Decommissioning. GEMBus provides common dynamically configurable messaging infrastructure for Composable services communication GEMBus is an ongoing development in the GN3 JRA3 Task 3 Composable Services activity Contributing Project GEANT3 JRA3 Task 3 – Composable services (GEMBus) - GEYSERS – Generalised Architecture for Infrastructure services - Yuri Demchenko, Cees de Laat (University of Amsterdam), Diego R. Lopez (RedIRIS), Joan A. Garcia Espin (I2CAT) [1] TeleManagement Forum Service Delivery Framework (SDF) - SDF Service Repository (ISS) SDF Service Lifecycle Metadata Coordination (ISS) SDF Service Design Management (ISS) SDF Service Deployment Management (ISS) SDF Service Provisng Mngnt (MSS) SDF Service Instance SDF Service Lifecycle Metadata Repository (ISS) Design Operate Deploy SDF Service Resource Fulfillment (ISS) SDF Service State Monitor (ISS) SDF Service Resource Monitor (ISS) SDF Service Resource Usage Monitor (ISS) SDF Service Quality/ Problem Mngnt (MSS) SDF Service Usage Mngnt (MSS) Composite Services provisioned on-demand SDF MSS SDF ISS Applications and User Terminals Composition Layer (Reservation SLA Negotiatn) Logical Abstraction Layer for Component Services and Resources Control & Management Plane (Operation, Orchestration) Composable Services Middleware (GEMBus) Network Infrastructure Compute Resources Storage Resources Component Services & Resources Proxy (adaptors/containers) - Component Services and Resources Proxy (adaptors/containers) – Composed/Virtualised Services and Resources MD SLC RegistryLoggingSecurity User Client GEMBus Infrastructure Services GEMBus Component Services Service 2 (CSrvID, SesID) GEMBus Registry Composition & Orchestration Logging Service Service 1 (CSrvID, SesID) Service 3 (CSrvID, SesID) Service 4 (CSrvID, SesID) GEMBus GEMBus Messaging Infrastructure (GMI) Routing Configuration Interceptors AspectOriented Security Service Message Handling CSrvID – Composite Service ID SesID – Provisioning Session ID CSA Incorporates the major principles of the Service Oriented Architecture (SOA) and supports SLM/SSLM services lifcecycle management models Logical Abstraction layer provides a basis for uniform component services presentation allowing federated cross-domain composite services operation. 3a DESIGN STAGE 9.Service Repository 10.Service Lifecycle Metadata Repository 14.Service Design Management DEPLOYMENT STAGE 10.Service Lifecycle Metadata Repository 11.Service Lifecycle Metadata Coordinator 15.Service Deployment Management OPERATION STAGE 5.Service Provisioning Management 6.Service Quality/Problem Management 7.Service Usage Monitor 9.Service State Monitor 10.Service Resource Fulfilment 11.Service Resource Monitor 12.Resource Usage Monitor