{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,12]],"date-time":"2025-11-12T03:11:04Z","timestamp":1762917064643,"version":"3.41.2"},"reference-count":51,"publisher":"Emerald","issue":"5","license":[{"start":{"date-parts":[[2006,10,1]],"date-time":"2006-10-01T00:00:00Z","timestamp":1159660800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2006,10,1]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>The purpose of this paper is that of linking security requirements for web services with security patterns, both at the architectural and the design level, obtaining in a systematic way a web services security software architecture that contains a set of security patterns, thus ensuring that the security requirements of the internet\u2010based application that have been elicited are fulfilled. Additionally, the security patterns are linked with the most appropriate standards for their implementation.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>To develop secure WS\u2010based applications, one must know the main security requirements specified that applications have to fulfil and find appropriate security patterns that assure, through combination or relationships between them, the fulfilment of the implicated security requirements. That is why a possible link or connection between requirements and patterns will have to be found, attempting to select for a determined security requirement the best security patterns that solve this requirement, thus guaranteeing the security properties for internet\u2010based applications.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>Using security patterns, that drive and guide one towards a secure development as well as towards security software architecture, one can be sure that this design based on these patterns fulfils and guarantees the most important security requirements of the internet\u2010based applications through the design and implementation of security solutions that provide reliable security services.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Practical implications<\/jats:title><jats:p>Security architecture for internet\u2010based applications and web services can be designed considering the security requirement types that it must fulfil and using the most appropriate security patterns.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>This paper proposes a relationship between security requirements that can be specified for internet\u2010based applications and the possible security patterns that can be used in the design and implementation of the secure system based on the internet, guaranteeing that these security requirements are fulfilled.<\/jats:p><\/jats:sec>","DOI":"10.1108\/10662240610710996","type":"journal-article","created":{"date-parts":[[2007,1,15]],"date-time":"2007-01-15T13:49:55Z","timestamp":1168868995000},"page":"519-536","source":"Crossref","is-referenced-by-count":17,"title":["Security patterns and requirements for internet\u2010based applications"],"prefix":"10.1108","volume":"16","author":[{"given":"David G.","family":"Rosado","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Carlos","family":"Guti\u00e9rrez","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eduardo","family":"Fern\u00e1ndez\u2010Medina","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mario","family":"Piattini","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2022031019555970400_b1","unstructured":"Alexander, C., Ishikawa, S., Silverstein, M., Jacobson, M., Fiksdahl\u2010King, I. and Angel, S. (1977), A Pattern Language: Towns, Buildings, Construction, Oxford University Press, New York, NY."},{"key":"key2022031019555970400_b2","unstructured":"Anderson, S., Bohren, J., Boubez, T., Chanliau, M., Della\u2010Libera, G., Dixon, B., Garg, P. and Gudgin, M. et al. (2005), Web Services Trust Language (WS\u2010Trust), February, available ftp:\/\/www6.software.ibm.com\/software\/developer\/library\/ws\u2010trust.pdf."},{"key":"key2022031019555970400_b3","doi-asserted-by":"crossref","unstructured":"Ashley, P., Hada, S., Karjoth, G. and Schunter, M. (2002), \u201cE\u2010P3P privacy policies and privacy authorization\u201d, Workshop on Privacy in the Electronic Society, WPES'02, Washington, DC.","DOI":"10.1145\/644527.644538"},{"key":"key2022031019555970400_b4","unstructured":"Bass, L., Clements, P. and Kazman, R. (2003), Software Architecture in Practice, Addison\u2010Wesley, Reading, MA."},{"key":"key2022031019555970400_b5","unstructured":"Berry, C.A., Carnell, J., Juric, M.B., Kunnumpurath, M.M., Nashi, N. and Romanosky, S. (2002), Chapter 5: Patterns Applied to Manage Security, J2EE Design Patterns Applied."},{"key":"key2022031019555970400_b6","unstructured":"Bilorusets, R., Bosworth, A., Box, D., Cabrera, L.F., Collison, D., Ferguson, D., Ferris, C. and Freund, T. (2004), Web Services Reliable Messaging Protocol (WS\u2010ReliableMessaging), March, available at:ftp:\/\/www6.software.ibm.com\/software\/developer\/library\/ws\u2010reliablemessaging200403.pdf."},{"key":"key2022031019555970400_b7","unstructured":"Buschmann, F. (1999), \u201cBuilding software with patterns\u201d, paper presented at the 2nd European Conference on Pattern Languages of Programs (EuroPLoP 1999), Irsee, Germany."},{"key":"key2022031019555970400_b8","unstructured":"Buschmann, F., Meunier, R., Rohnert, H., Sommerlad, P. and Stal, M. (1996), Pattern\u2010Oriented Software Architecture: A System of Patterns, John Wiley, New York, NY."},{"key":"key2022031019555970400_b9","unstructured":"CERT (2006), Statistics 1988\u20102006, available at: www.cert.org\/stats\/cert_stats.html#incidents."},{"key":"key2022031019555970400_b10","unstructured":"Cranor, L., Langheinrich, M. and Marchiori, M. (2002), A P3P Preference Exchange Language 1.0 (APPEL1.0). W3C Working Draft, available at: www.w3.org\/TR\/2002\/WD\u2010P3P\u2010preferences\u201020020415\/."},{"key":"key2022031019555970400_b11","unstructured":"Curbera, F., Nagy, W.A. and Weerawarana, S. (2001), \u201cWeb services: why and how\u201d, Workshop on Object Orientation and Web Services OOWS2001, Tampa, FL."},{"key":"key2022031019555970400_b12","unstructured":"Cheng, B.H.C., Konrad, S., Campbell, L.A. and Wassermann, R. (2003), \u201cUsing security patterns to model and analyze security requirements\u201d, High Assurance Systems Workshop (RHAS 03) as part of the IEEE Joint International Conference on Requirements Engineering (RE 03), Monterey Bay, CA."},{"key":"key2022031019555970400_b13","unstructured":"Das Neves, F. and Garrido, A. (1998), BodyGuard, Pattern Languages of Programs III, Addison\u2010Wesley, Reading, MA."},{"key":"key2022031019555970400_b14","doi-asserted-by":"crossref","unstructured":"Ellison, C., Frantz, B., Lampson, B., Rivest, R., Thomas, B., Bell, S. and Ylonen, T. (1999), SPKI Certificate Theory, Internet Eng. Task Force RFC 2693.","DOI":"10.17487\/rfc2693"},{"key":"key2022031019555970400_b15","unstructured":"Evans, C., Chappell, D., Bunting, D., Tharakan, G., Shimamura, H., Durand, J., Mischkinsky, J. and Nihei, K. et al. (2003), Web Services Reliability (WS\u2010Reliability) Ver1.0. January 8, available at: www.oracle.com\/technology\/tech\/webservices\/htdocs\/spec\/WS\u2010ReliabilityV1.0.pdf."},{"key":"key2022031019555970400_b17","unstructured":"Fernandez, E.B. (2002), \u201cPatterns for operating systems access control\u201d, paper presented at the 9th Conference on Pattern Languages of Programs, PLoP 2002, Allerton Park, IL."},{"key":"key2022031019555970400_b18","unstructured":"Fernandez, E.B. and Pan, R. (2001), \u201cA pattern language for security models\u201d, paper presented at the 8th Conference on Pattern Languages of Programs, PLoP 2001, Allerton Park, Monticello, IL."},{"key":"key2022031019555970400_b19","unstructured":"Fernandez, E.B., Petrie, M.L., Seliya, N. and Herzberg, A. (2003), \u201cA pattern language for firewalls\u201d, paper presented at the 10th Conference on Pattern Languages of Programs (PLoP'2003), Allerton Park, Monticello, IL."},{"key":"key2022031019555970400_b20","doi-asserted-by":"crossref","unstructured":"Firesmith, D.G. (2003), \u201cEngineering security requirements\u201d, Journal of Object Technology, Vol. 2 No. 1, pp. 53\u201068.","DOI":"10.5381\/jot.2003.2.1.c6"},{"key":"key2022031019555970400_b21","doi-asserted-by":"crossref","unstructured":"Firesmith, D.G. (2004), \u201cSpecifying reusable security requirements\u201d, Journal of Object Technology, Vol. 3, pp. 61\u201075.","DOI":"10.5381\/jot.2004.3.1.c6"},{"key":"key2022031019555970400_b22","unstructured":"Flanders, R. and Fernandez, E.B. (1999), \u201cData filter architecture pattern\u201d, paper presented at the 6th Conference on Pattern Languages of Programs, PLoP 1999, Allerton Park, Monticello, IL."},{"key":"key2022031019555970400_b23","unstructured":"Ford, W., Hallam\u2010Baker, P., Fox, B., Dillaway, B., LaMacchia, B., Epstein, J. and Lapp, J. (2001), XML Key Management Specification (XKMS). W3C Note 30, VeriSign Inc, Microsoft Corporation, webMethods Inc., London."},{"key":"key2022031019555970400_b24","unstructured":"Fox, S. (2001), Collection and Dissemination of Computer and Internet Security Related Information (Alerts, Advisories, Incident Notes, Vulnerability Notes, Summaries and other Bulletins), SANS.org, Washington, DC, August 21."},{"key":"key2022031019555970400_b25","doi-asserted-by":"crossref","unstructured":"Guti\u00e9rrez, C., Fern\u00e1ndez\u2010Medina, E. and Piattini, M. (2004), \u201cWeb services security: is the problem solved?\u201d, Information Systems Security, Vol. 13, pp. 22\u201031.","DOI":"10.1201\/1086\/44530.13.3.20040701\/83066.4"},{"key":"key2022031019555970400_b26","doi-asserted-by":"crossref","unstructured":"Guti\u00e9rrez, C., Fern\u00e1ndez\u2010Medina, E. and Piattini, M. (2005a), \u201cPWSSec: process for web services security\u201d, paper presented at the IEEE International Conference on Web Services, Orlando, FL.","DOI":"10.1109\/ICWS.2006.107"},{"key":"key2022031019555970400_b27","unstructured":"Guti\u00e9rrez, C., Fern\u00e1ndez\u2010Medina, E. and Piattini, M. (2005b), \u201cWeb services\u2010based security requirement elicitation\u201d, paper presented at 1st International Workshop on Service\u2010Oriented Computing: Consequences for Engineering Requirements (SOCCER 2005), in conjunction with RE 05 \u2013 13th IEEE International Requirements Engineering Conference, Paris, France."},{"key":"key2022031019555970400_b28","doi-asserted-by":"crossref","unstructured":"Guti\u00e9rrez, C., Fern\u00e1ndez\u2010Medina, E. and Piattini, M. (2005c), \u201cWeb services enterprise security architecture: a case study\u201d, Workshop on Security on Web Services, Fairfax, VA.","DOI":"10.1145\/1103022.1103025"},{"key":"key2022031019555970400_b29","doi-asserted-by":"crossref","unstructured":"Housley, R., Ford, W., Polk, W. and Solo, D. (1999), Internet X.509 Public Key Infrastructure Certificate and CRL Profile, Internet Eng. Task Force RFC 2459, January.","DOI":"10.17487\/rfc2459"},{"key":"key2022031019555970400_b30","unstructured":"IBM (2002), Security in a Web Services World: A Proposed Architecture and Roadmap. White Paper from IBM Corporation and Microsoft Corporation, Version 1.0, available at: www.verisign.com\/wss\/architectureRoadmap.pdf."},{"key":"key2022031019555970400_b31","unstructured":"IDC (2005), Consumption of Web Services Will Greatly Increase through 2009, available at: www.idc.com\/getdoc.jsp?containerId=prUS00190705."},{"key":"key2022031019555970400_b32","unstructured":"Imamura, T. and Tatsubori, M. (2003), \u201cPatterns for securing web services messaging\u201d, OOPSLA'03 Workshop for Web Services and Service Oriented Architecture Best Practice and Patterns, Anaheim, CA."},{"key":"key2022031019555970400_b33","unstructured":"Kis, M. (2002), \u201cInformation Security antipatterns in software requirements engineering\u201d, paper presented at the 9th Conference on Pattern Languages of Programs (PLoP'2002), Allterton Park, Monticello, IL."},{"key":"key2022031019555970400_b16","unstructured":"Lee Brown, J.F., DiVietri, J., Diaz de Villegas, G. and Fernandez, E.B. (1999), \u201cThe authenticator pattern\u201d, paper presented at the 6th Conference on Pattern Languages of Programs, PLoP 1999, Allerton Park, Monticello, IL."},{"key":"key2022031019555970400_b34","unstructured":"Lehtoren, S. and P\u00e4rssinen, J. (2002), \u201cPattern language for cryptographic key management\u201d, paper presented at the 7th European Conference on Pattern Languages of Programs (EuroPlop'2002), Irsee, Germany."},{"key":"key2022031019555970400_b35","unstructured":"OASIS (2003), Assertions and Protocol for the OASIS Security Assertion Markup Language (SAML) V1.1, available at: www.oasis\u2010open.org\/committees\/download.php\/3406\/oasis\u2010sstc\u2010saml\u2010core\u20101.1.pdf."},{"key":"key2022031019555970400_b36","unstructured":"OASIS (2005), Quality Model for Web Services, Available at: www.oasis\u2010open.org\/committees\/download.php\/15910\/WSQM\u2010ver\u20102.0.doc."},{"key":"key2022031019555970400_b37","unstructured":"OASIS (2006a), Web Services Security. X.509 Certificate Token Profile 1.1. OASIS Standard Specification, available at: www.oasis\u2010open.org\/committees\/download.php\/16785\/wss\u2010v1.1\u2010spec\u2010os\u2010x509TokenProfile.pdf."},{"key":"key2022031019555970400_b38","unstructured":"OASIS (2006b), Web Services Security. Username Token Profile 1.1. OASIS Standard Specification, 1 February, available at: www.oasis\u2010open.org\/committees\/download.php\/16782\/wss\u2010v1.1\u2010spec\u2010os\u2010UsernameTokenProfile.pdf."},{"key":"key2022031019555970400_b39","unstructured":"OASIS (2006c), Web Services Security. Kerberos Token Profile 1.1. OASIS Standard Specification, 1 February, available at: www.oasis\u2010open.org\/committees\/download.php\/16788\/wss\u2010v1.1\u2010spec\u2010os\u2010KerberosTokenProfile.pdf."},{"key":"key2022031019555970400_b40","unstructured":"OASIS (2006d), Web Services Security. SOAP Message Security 1.1 (WS\u2010Security 2004). OASIS Standard Specification, 1 February, available at: www.oasis\u2010open.org\/committees\/download.php\/16790\/wss\u2010v1.1\u2010spec\u2010os\u2010SOAPMessageSecurity.pdf."},{"key":"key2022031019555970400_b41","unstructured":"Ramachandran, J. (2002), Designing Security Architecture Solutions, John Wiley, New York, NY."},{"key":"key2022031019555970400_b42","unstructured":"Romanosky, S. (2001), Security Design Patterns, available at: www.cgisecurity.com\/lib\/securityDesignPatterns.html."},{"key":"key2022031019555970400_b43","unstructured":"Romanosky, S. (2002), \u201cEnterprise security patterns\u201d, paper presented at the 7th European Conference on Pattern Languages of Programs (EuroPlop'02), Irsee, Germany."},{"key":"key2022031019555970400_b44","unstructured":"Rosado, D.G., Guti\u00e9rrez, C., Fernandez\u2010Medina, E. and Piattini, M. (2006), \u201cA study of security architectural patterns\u201d, paper presented at the 1st International Conference on Availability, Reliability and Security (ARES 2006), Vienna, Austria, IEEE Computer Society, available at: http:\/\/csdl.computer.org\/dl\/proceedings\/ares\/2006\/2567\/00\/25670358.pdf."},{"key":"key2022031019555970400_b45","unstructured":"Steel, C., Nagappan, R. and Lai, R. (2005), Core Security Patterns, Prentice\u2010Hall, Englewood Cliffs, NJ."},{"key":"key2022031019555970400_b46","unstructured":"Todd, S., Parr, F. and Conner, M. (2001), A Primer for HTTPR. An Overview of the Reliable HTTP Protocol, IBM, available at: www\u2010128.ibm.com\/developerworks\/webservices\/library\/ws\u2010phtt\/."},{"key":"key2022031019555970400_b47","unstructured":"W3C (2004), Services Architecture, available at: www.w3.org\/TR\/2004\/NOTE\u2010ws\u2010arch\u201020040211\/."},{"key":"key2022031019555970400_b48","unstructured":"WS\u2010I (2005), Security Challenges, Threats and Countermeasures Version 1.0.T. Report, available at: www.ws\u2010i.org\/Profiles\/BasicSecurity\/SecurityChallenges\u20101.0\u201020050507.doc."},{"key":"key2022031019555970400_b50","doi-asserted-by":"crossref","unstructured":"Yag\u00fce, M.I. and Troya, J.M. (2002), \u201cA semantic approach for access control in web services\u201d, paper presented at the Euroweb 2002 International Conference, W3C & British Computer Society Electronic Workshops in Computing (eWiC), Oxford.","DOI":"10.14236\/ewic\/EW2002.3"},{"key":"key2022031019555970400_b49","doi-asserted-by":"crossref","unstructured":"Yag\u00fce, M.I., Ma\u00f1a, A. and L\u00f3pez, J. (2005), \u201cA metadata\u2010based access control model for web services\u201d, Internet Research Journal: Electronic Networking Applications and Policy, Vol. 25 No. 1, pp. 99\u2010116.","DOI":"10.1108\/10662240510577095"},{"key":"key2022031019555970400_b51","unstructured":"Yoder, J. and Barcalow, J. (1997), \u201cArchitectural patterns for enabling application security\u201d, paper presented at the 4th Conference on Patterns Language of Programming, PLop 1997, Monticello, IL."}],"container-title":["Internet Research"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/10662240610710996","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/10662240610710996\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/10662240610710996\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,24]],"date-time":"2025-07-24T23:40:10Z","timestamp":1753400410000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/intr\/article\/16\/5\/519-536\/186150"}},"subtitle":[],"editor":[{"given":"Mariemma","family":"Yague","sequence":"first","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]}],"short-title":[],"issued":{"date-parts":[[2006,10,1]]},"references-count":51,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2006,10,1]]}},"alternative-id":["10.1108\/10662240610710996"],"URL":"https:\/\/doi.org\/10.1108\/10662240610710996","relation":{},"ISSN":["1066-2243"],"issn-type":[{"type":"print","value":"1066-2243"}],"subject":[],"published":{"date-parts":[[2006,10,1]]}}}