• DocumentCode
    2695002
  • Title

    Applying Sanitizable Signature to Web-Service-Enabled Business Processes: Going Beyond Integrity Protection

  • Author

    Tan, Kar Way ; Deng, Robert H.

  • Author_Institution
    Sch. of Inf. Syst., Singapore Manage. Univ., Singapore, Singapore
  • fYear
    2009
  • fDate
    6-10 July 2009
  • Firstpage
    67
  • Lastpage
    74
  • Abstract
    This paper studies the scenario where data in business documents is aggregated by different entities via the use of Web services in streamlined business processes. The documents are transported within the Simple Object Access Protocol (SOAP) messages and travel through multiple intermediary entities, each potentially makes changes to the data in the documents. The WS-security provides integrity protection by allowing portions of a SOAP message to be signed using eXtensible Markup Language (XML) signature scheme. This method however, has not considered the situation where a portion of data may be modified by another entity, therefore a need to allow the originating system to control which intermediary entity is authorized to change which portion of the data. The XML signature scheme also does not provide the final recipient the trust for the intermediary entity that makes the changes. In our paper, we study the security requirements for a streamlined business process, and proposes a novel scheme using sanitizable signature on SOAP messages to complement the XML signature to address not only integrity protection but also control of change as well as establishment of trust for intermediary entities. We show how the proposed scheme can be incorporated into the existing standards and be customizable to achieve flexible use of both the vanilla and sanitizable signatures as required in a business scenario. With the proposed technique, IT systems can be more loosely coupled and reap the benefits of distributed systems, such as delegation of work and encapsulation of business logic.
  • Keywords
    Web services; XML; access protocols; business data processing; digital signatures; IT system; SOAP message; Simple Object Access Protocol; WS-security; Web service-enabled business process; XML signature; business document; business logic; distributed system; eXtensible Markup Language; integrity protection; sanitizable signature; security requirement; streamlined business process; work delegation; Conference management; Control systems; Data security; Encapsulation; Information management; Management information systems; Protection; Simple object access protocol; Web services; XML; SOAP message security; Web services; XML signature; integrity protection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Web Services, 2009. ICWS 2009. IEEE International Conference on
  • Conference_Location
    Los Angeles, CA
  • Print_ISBN
    978-0-7695-3709-2
  • Type

    conf

  • DOI
    10.1109/ICWS.2009.34
  • Filename
    5175808