Hier finden Sie wissenschaftliche Publikationen aus den Fraunhofer-Instituten.

Secure mashup-providing platforms - implementing encrypted wiring

: Herbert, Matthias; Thieme, Tobias; Zibuschka, Jan; Roßnagel, Heiko


Harth, A.:
Current Trends in Web Engineering : Workshops, Doctoral Symposium, and Tutorials, Held at ICWE 2011, Paphos, Cyprus, June 20-21, 2011. Revised Selected Papers
Berlin: Springer, 2012 (Lecture Notes in Computer Science 7059)
ISBN: 978-3-642-27996-6 (Print)
ISBN: 978-3-642-27997-3
ISSN: 0302-9743
International Conference on Web Engineering (ICWE) <11, 2011, Paphos/Cyprus>
Fraunhofer IAO ()

Mashups were not designed with security in mind. Their main selling point is the flexible and easy to use development approach. The fact that mashups enable users to compose services to create a piece of software with new functionalities, integrating inputs from various sources, implies a security risk. However, in many scenarios where mashups add business value, e.g. enterprise mashups, security and privacy are important requirements. A secure environment for the handling of potentially sensitive end user information is needed, unless the user fully trusts the mashup-providing-platform (MPP), which is unlikely for hosted enterprise mashups. In this paper we present a proof-of-concept implementation which enables the secure usage of a mashup-providing platform and protects sensitive data against malicious widgets and platform operators.