DocumentCode :
2355026
Title :
Considering web services security policy compatibility
Author :
Lavarack, Tristan ; Coetzee, Marijke
Author_Institution :
Acad. for Inf. Technol., Univ. of Johannesburg, Gauteng, South Africa
fYear :
2010
fDate :
2-4 Aug. 2010
Firstpage :
1
Lastpage :
8
Abstract :
For most organizations supporting business-to-business (B2B) web services interactions, security is a growing concern. Web services providers and consumers document their primary and alternative security policy requirements and capabilities in security policy files, defined by WS-Policy, WS-SecurityPolicy and WS-Security syntax. To secure message exchanges to the satisfaction of all parties, the security requirements of both web services providers and consumers need to be satisfied. This paper investigates how mutually agreed-upon security policies can be created. An analysis of the policy intersection algorithm highlights its deficiencies for finding mutually compatible policies. The interrelated effect that security policy assertion choices have on each other is identified as an important aspect not yet considered. Over and above security policy assertions, other influence on security policy choices, which may affect the security level supported by the organization, is identified. A proposal is made on how the assertions of two security policies should be considered, in order to create a secure, mutually agreed-upon security policy that will satisfy the requirements of both parties.
Keywords :
Web services; business data processing; computer network security; law; WS- SecurityPolicy; WS-Policy; WS-Security syntax; Web service security policy compatibility; business to business Web service interaction; mutually agreed upon security policy; policy intersection algorithm; Authentication; Encryption; Simple object access protocol; XML; WS-Policy; WS-SecurityPolicy; policy compatibility; policy intersection; security policy assertions;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Security for South Africa (ISSA), 2010
Conference_Location :
Sandton, Johannesburg
Print_ISBN :
978-1-4244-5493-8
Type :
conf
DOI :
10.1109/ISSA.2010.5588269
Filename :
5588269
Link To Document :
بازگشت