Abstract
The Service Availability Forum is specifying high availability interfaces for carrier grade applications. Along with the direct support for applications an implementation of these interfaces implies that it can itself be highly available. To ensure this availability an implementation must be secure, but these security mechanisms must themselves not reduce the availability of the overall system [1,2]. The security of high availability interfaces (and their middleware implementations) therefore requires a careful design to address potential cross influences.
In this paper, we first discuss the general security scope for SA Forum systems, do a threat analysis and list a number of assumption of the execution environment. Then, we present a strawman architecture for the SA Forum Security service (SEC). Rather than presenting a detailed design, with this architecture we attempt to provide guidance, expose issues to be addressed and offer solution ideas for those issues.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
Reitenspiess, M.: Availability in Industry and Science - A Business Perspective -. In: Dal Cin, M., Kaâniche, M., Pataricza, A. (eds.) EDCC 2005. LNCS, vol. 3463, pp. 226–229. Springer, Heidelberg (2005), http://www.springerlink.com/index/10.1007/11408901_17
Dierstein, R.: Sicherheit in der Informations technik - der Begriff IT-Sicherheit. Informatik Spektrum Bd. 24, Heft 4, August 2004, 343–353 (2004)
Service Availability Forum (SA Forum), http://www.saforum.org/home
Shahane, M.: Open standards for high availability and system management (2005), http://www.embedded-control-europe.com/pdf/basapr05p31.pdf
HPI-B.01.01 Service Availability Forum Hardware Platform Interface, version B.01.01, http://www.saforum.org/specification/HPI_Specification
Service Availability Forum, Service Availability Interface, Overview document, SAI-Overview-B.01.04, Candidate B.02.01
Service Availability Forum, Distributed Systems Management, Distributed Systems Management for AIS-SNMP SAI-SMS-AIS-SNMP-A-01-01
Service Availability Forum, Distributed Systems Management, Distributed Systems Management for HPI-SNMP SAI-SMS-HPI-SNMP-B-01-01
Kamalvanshi, J.: Build the next generation of telecom systems with open interfaces, Part 2 (2005), http://www.commsdesign.com/design_corner/showArticle.jhtml;jsessionid=OB3CJKWTFE3QQQSNDBCCKHSCJUMEKJVN?articleID=163700304
Carrier Grade Linux, http://www.osdl.org/lab_activities/carrier_grade_linux
Service Availability Forum, System Management Specification, vol. 10: Log Service, SAI-AIS-LOG-A.01-01
Service Availability Forum, Application Interface Specification, vol. 9: Notification Service, SAI-AIS-NTF-A.01.01
Security Assertion Markup Language (SAML), http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=security
eXtensible Access Control Markup Language (XACML), http://www.oasis-open.org/specs/index.php#xacmlv2.0
SNMP, SNMPv2, SNMPv3, and RMON 1 and 2. William Stallings. Addison Wesley, Reading (1999)
CIM Specification 2.3. Distributed Management Task Force, http://www.dmtf.org/standards/cim/ http://www.dmtf.org/
Service Availability Forum, Application Interface Specification, vol. 2: Availability Management Framework, SAI-AIS-AMF-B.02.01
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2006 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Badovinatz, P., Balakrishnan, S., Pourzandi, M., Reitenspiess, M., Tindel, C. (2006). The Service Availability Forum Security Service (SEC): Status and Future Directions. In: Penkler, D., Reitenspiess, M., Tam, F. (eds) Service Availability. ISAS 2006. Lecture Notes in Computer Science, vol 4328. Springer, Berlin, Heidelberg. https://doi.org/10.1007/11955498_19
Download citation
DOI: https://doi.org/10.1007/11955498_19
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-540-68724-5
Online ISBN: 978-3-540-68725-2
eBook Packages: Computer ScienceComputer Science (R0)