DocumentCode :
2132841
Title :
Streaming-Based Verification of XML Signatures in SOAP Messages
Author :
Somorovsky, Juraj ; Jensen, Meiko ; Schwenk, Jörg
Author_Institution :
Horst Gortz Inst. for IT Security, Ruhr Univ., Bochum, Germany
fYear :
2010
fDate :
5-10 July 2010
Firstpage :
637
Lastpage :
644
Abstract :
WS-Security is a standard providing message-level security in Web Services. Therewith, it ensures their integrity, confidentiality, and authenticity. However, using sophisticated security algorithms can lead to high memory consumptions and long evaluation times. In combination with the standard DOM approach for XML processing, the Web Services servers easily become a target of Denial-of-Service attacks. We present a solution for these problems: an external streaming-based WS-Security Gateway. Our implementation is capable of processing XML Signatures in SOAP messages using a streaming-based approach. The evaluation shows that such an approach greatly enhances the performance and is much more efficient in comparison to standard DOM-based frameworks.
Keywords :
Web services; XML; authorisation; computer network security; digital signatures; DOM approach; SOAP messages; WS-security; Web services; XML signature; authenticity; confidentiality; denial-of-service attack; integrity; message level security; Logic gates; Memory management; Security; Servers; Simple object access protocol; XML; Performance; Streaming-based processing; WS-Security; Web Services; XML Signature;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Services (SERVICES-1), 2010 6th World Congress on
Conference_Location :
Miami, FL
Print_ISBN :
978-1-4244-8199-6
Electronic_ISBN :
978-0-7695-4129-7
Type :
conf
DOI :
10.1109/SERVICES.2010.57
Filename :
5575516
Link To Document :
بازگشت