|
> Congress / Advance Programme / Workshops / Ws3
Ws3: Certification and Security in Inter-Organizational E-Services (CSES-04)
26- 27 August 2004
http://www.nestor.uniroma2.it/cses2004/main.htm
General co-Chairs
Enrico Nardelli and MaurizioTalamo (NESTOR - U. Rome "TorVergata", Italy)
Scope and topics
The objective of the International Workshop on Certification and Security in Inter-Organizational E-Services (CSES-04) is to discuss technical and organizational aspects regarding the two interrelated areas of certification and security of e-services, presenting both real-life application experiences and methodological proposals, from participants belonging to the governmental, industrial and academic communities.
The field of services managed and accessed through communication networks is, in fact, growing in magnitude throughout society. A crucial aspect of this process is the capability of certifying what has occurred in the interaction over the networks, and ensuring that the integrity of the involved computer-based systems was maintained. This is even more important given the uptake of distributed computational infrastructure oriented to service provision, like Web- Services and Grid.
Certifying the execution of an e-service provided on the network as the result of the interaction among independent organizations is a critical area for the underlying IT-infrastructure. In fact, given the legal value that is often attached to data managed and exchanged during the execution of such an inter-organizational e-service, being able to document what was actually carried out is of the utmost importance. This is made more complex in cases where e-services are based on legacy systems managed by autonomous and independent organizations, as often happens in the public administration sector.
Additionally, the whole area of security issues, from the basic (availability, authentication, integrity, confidentiality) to the more complex (e.g., authorization, non-repudiation) involves the equally critical ability to track down responsibilities ("who did what"). This capability is mandatory to increase the presence and use of e-service IT-infrastructures.
The two areas of certification and security have therefore a common technological intersection, since both are based on the reliable and efficient monitoring of executed and running processes. Monitoring requires the capability of tracing and analyzing what is going on in the distributed system and in the underlying IT-infrastructure. Monitoring is also important for contractual and quality reasons, i.e. to serve as a basis for checking the respect of obligation and duties and the value of performance levels.
Contact
cses2004@nestor.uniroma2.it

|