DocumentCode
2392789
Title
A message interaction security mechanism based on SOA
Author
Wei, Ran ; Qiao, Lixiang ; Yang, Zhimin
Author_Institution
Dept. of Comput. Sci., Shandong Univ. at Weihai, Weihai, China
fYear
2012
fDate
19-20 May 2012
Firstpage
1503
Lastpage
1506
Abstract
At present, SOA (Service-Oriented Architecture) is already widely applied in the enterprise commercial development as it is loose coupling, cross-platform, language-independent, supporting organic businesses architecture. Security for communication between services has become a key technology which restricts SOA and Web services to continue to develop. Network attackers can keep the signature and certification sections of the message unchanged and modify the SOAP messages by removing or adding some elements in the head or the body part at the same time. Current security mechanisms rarely consider the effective use of the structure of the SOAP message itself to detect this type of tampering attacks. Here we give a mechanism using the structured information of SOAP Further to spot XML tampering attacks and make the appropriate details of the principle and implementation. Experiments prove that using this mechanism we can choose different security levels more flexibly without affecting the system efficiency while maintaining the security.
Keywords
Web services; XML; security of data; service-oriented architecture; SOA; SOAP messages; Web services; XML tampering attacks; enterprise commercial development; message interaction security mechanism; network attackers; organic businesses architecture; service-oriented architecture; structured information; Protocols; Safety; Security; Service oriented architecture; Simple object access protocol; XML; Message layer security mechanisms; SOA; SOAP; Web Services;
fLanguage
English
Publisher
ieee
Conference_Titel
Systems and Informatics (ICSAI), 2012 International Conference on
Conference_Location
Yantai
Print_ISBN
978-1-4673-0198-5
Type
conf
DOI
10.1109/ICSAI.2012.6223322
Filename
6223322
Link To Document