• DocumentCode
    2924564
  • Title

    Tutorial 6: Security in SOA and Web Services

  • Author

    Bertino, Elisa ; Martino, Luca

  • Author_Institution
    Dept. of Comput. Sci., Purdue Univ., West Lafayette, IN
  • fYear
    2006
  • fDate
    18-22 Sept. 2006
  • Abstract
    Security is today a relevant requirement for any distributed application, and in particular for these enabled by the Web such as e-health, e-commerce, and e-learning. It is thus crucial that the use of Web services, stand-alone or composed, provide strong security guarantees. Web services security encompasses several requirements that can be described along the well known security dimensions, that is: integrity, whereby a message must remain unaltered during transmission; confidentiality, whereby the contents of a message cannot be viewed while in transit, except by authorized services; availability, whereby a message is promptly delivered to the intended recipient, thus ensuring that legitimate users receive the services they are entitled to. Moreover, each Web service must protect its own resources against unauthorized access. This in turn requires suitable means for: identification, whereby the recipient of a message must be able to identify the sender; authentication, whereby the recipient of a message needs to verify the claimed identity of the sender; authorization, whereby the recipient of a message needs to apply access control policies to determine whether the sender has the right to use the required resources. In the tutorial we will first discuss the main security requirements underlying the interactions between clients and Web services and among the Web services themselves. Then we will describe how such security requirements are addressed by standards for Web services security recently developed or under development by various standardizations bodies. Standards that are covered include: WSS, that encompasses a large number of components addressing various security aspects; XACML, that is related to access control and has been recently extended with a profile for Web services access control; WS-Federation, Liberty Alliance and Shibboleth, that address the important problem of identity management in federated organizations. Issues related to the use of t- ese standards are discussed. Then, research approaches to the problem of Web service security will be surveyed, including negotiation-based access control for Web services, and access control for conversation-based Web services
  • Keywords
    Web services; authorisation; Liberty Alliance; SOA security; Shibboleth; WS-Federation; WSS standard; Web service security; Web services access control; XACML standard; conversation-based Web services; distributed application; identity management; negotiation-based access control; security requirements;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Web Services, 2006. ICWS '06. International Conference on
  • Conference_Location
    Chicago, IL
  • Print_ISBN
    0-7695-2669-1
  • Type

    conf

  • DOI
    10.1109/ICWS.2006.141
  • Filename
    4032005