A way to move towards a service-oriented architecture, is for the application managed approach to re-focus on security as an API/SPI interface with SPI providers adhering to standardized interfaces (e.g., JAAS, JACC, web services based authorization). Within a service-oriented architecture, the applications can then move to an infrastructure managed approach to security as a first step. Migrating security is not something that is achieved overnight (if ever). It is important to move towards this approach in a logical manner. The first step is to move as much of the application managed security functionality towards implementation of standardized interfaces for security providers. This starts the process of common security functionality, as shown in Figure 6, below.



Brokering Security through a Reverse Proxy

Another step along the path to a service-oriented architecture is to introduce a specialized component, in this case a reverse proxy server to the architecture, as shown in Figure 7. This component is typically already a part of many Enterprise architectures, where it is used to provide perimeter-based security services for the Enterprise. A reverse proxy moves authentication functionality to the edge (or perimeter) of the network, so that only authenticated users are allowed into the Trusted Network. This front-end component may also provide coarse-grained access control decisions, eliminating unauthorized requests to the back-end resources. These access control decisions may be coarse-grained (the user is authenticated and therefore access can be granted) or fine-grained (the user is not a member of the group/does not have the role required to access the requested resource) if the information required to make the fine-grained decision is available to the edge-based decision point.

Figure 4: Moving Towards Infrastructure Managed Security: Reverse Proxy Pattern

This additional step consolidates security functionality to a single logical point (the reverse proxy server) thus identifying a common security point. This common security point in turn provides an opportunity to define a common security service, a core component of SOA. A common security service can also help with systems management issues eliminating the need for detailed knowledge of authorization decisions in the back-end application as part of the fulfillment of that application.

4

  • Subscribe
  • Contribute

Welcome back Jason!

You are subscribed to 4 of our newsletters. We offer 6 more reports that help you keep on top of your Business and IT Agility priorities.
Manage your subscriptions

ebizQ is very interested in what you have to say. To contribute an article, an opinion, or to become a blogger, please contact Jessica Ann Mola.

  • Virtual Conferences
  • Webinars
  • Roundtables

SOA in Action

Oct 28-29, 2009

SOA is ready for the business. But is the business ready for SOA?
Welcome to Service-Oriented Architecture, phase two. Six years after SOA first hit the mainstream, many organizations have achieved strong value, while some are struggling to realize business results from this increasingly popular approach to technology deployment. Some challenging hurdles remain in the "Increase SOA value to the business" journeyRegister

View All Virtual Conferences

The Future of Content Management is Vertical

Date: Feb 10, 2010
Time: 12:00 PM ET- (17:00 GMT)

REGISTER TODAY!
View All Webinars

How Continuous Intelligence Improves Your Business Processes

Date:Feb 02, 2010
Time:12:00 PM ET- (17:00 GMT)

REGISTER TODAY!

Understanding and Estimating the Business Value of Data Virtualization

Date:Nov 18, 2009
Time:12:00 PM ET- (17:00 GMT)

REGISTER TODAY!
View All Roundtables
  • White Papers
  • Podcasts
  • News

Joe McKendrick: Part II of II: Designing Evolve-ability into SOA and IT Systems

In part two of Joe McKendrick's recent podcast with Miko Matsumura, chief strategist for Software AG, they talk about how SOA and IT systems need to change and grow and adapt with the organization around it.

Listen Now

Phil Wainewright: Helping Brands Engage with Social Media

Phil Wainewright interviews David Vap, VP of products at RightNow Technologies, and finds out how sharing best practices can help businesses understand how best to engage with online communities.

Listen Now

Peter Schooff: Making Every IT Dollar Result in a Desired Business Outcome: Scott Hebner of IBM Rati

Scott Hebner, Vice President of Marketing and Strategy for IBM Rational, discusses a topic on the top of every company's mind today: getting the most from IT investments.

Listen Now

Jessica Ann Mola: Where Will BI Fit In? Lyndsay Wise Explains

In BI, this tough economy and the increasing role of Web 2.0 and MDM are certainly topics on people's minds today. WiseAnalytics' Lyndsay Wise addresses each of them in this informative podcast.

Listen Now

Dennis Byron: Talking with...Deepak Singh of BPM Provider Adeptia

Deepak Singh, President and CTO of Adeptia, joins ebizQ's Dennis Byron in a podcast that gets its hand around the trend of industry-specific BPM.

Listen Now
More Podcasts
  • Most Popular
  • Quick Guide
  • Most Discussed

Quick Guide: What is Event Processing?

Smart event processing can help your company run smarter and faster. This comprehensive guide helps you research the basics of complex event processing (CEP) and learn how to get started on the right foot with your CEP project using EDA, RFID, SOA, SCADA and other relevant technologies. Learn More

Quick Guide: What is Enterprise 2.0?

A lot of people are talking about Enterprise 2.0 as being the business application of Web 2.0 technology. However, there's still some debate on exactly what this technology entails, how it applies to today's business models, and which components bring true value. Some use the term Enterprise 2.0 exclusively to describe the use of social networking technologies in the enterprise, while others use it to describe a web economy platform, or the technological framework behind such a platform. Still others say that Enterprise 2.0 is all of these things. Learn More

Quick Guide: What is BPM?

Learn More