A Public Web Services Security Framework Based on Current and Future Usage Scenarios
نویسندگان
چکیده
—This paper discusses the security implications of Web Services and proposes a framework for providing security based on current and future requirements. The framework provides a basis for achieving end-to-end security for Web Services within the pre-existing security environment. Finally, lessons from initial experiences with Web Services security and advice for the future are provided. Web Services require stronger security than Web sites. They expose functionality (typically business logic) in an open, standardized way. This implies that they are more vulnerable than when business processes were exposed in proprietary ways. This means that security will become an automatic part of any Web Services development. In addition, Web Services will be interwoven with existing applications, so the Web Services security must also accommodate existing security infrastructure. The new Web Services security software and protocols are interesting, but suffer from immaturity, lack of widespread adoption (no critical mass), and lack of technical staff with specific knowledge. The first wave of Web Services, and the products used to build them, have used well-known and accepted security technology (such as access control and authentication) that have been borrowed from the Internet and the World Wide Web. However, Web Services have not reached beyond the requirement for basic security. The objective of this paper is to describe a public framework for Web Services, based on an analysis of current and near-future usage scenarios for Web Services. There is a long-term vision for Web Services where there will be " millions of Web Services " commercially available to consumers and organizations will use Web Services to expose systems to customers and partners. However, in the meantime, the most immediate use of Web Services is for tactical projects that rely on the technical advantages offered by Web Services: • Enterprise Application Integration: SOAP can be used to integrate Java and EJBs with logic deployed in other enterprise systems such as CORBA and .NET. The best initial projects for Web Services in organizations often involve the reuse of existing back-end systems – with Web Services used to expose them in a new way. This approach has the added benefit that the focus of the project has been the Web Services rather than developing some new business logic. For internal integration, the security implications for this have tended to depend on factors such as the sensitivity of the internal information being passed around and whether the information ever moves …
منابع مشابه
تدوین سناریوهای متصور برای آینده نهاد رسانهای کتابخانههای عمومی ایران
Purpose: The aim of the current research is to write possible scenarios for the future of Iran's public libraries. Regarding the position and application of public libraries, they are considered as a communicative medium. Methodology: The effort is to offer scenarios that deal with the multiplicity and unpredictability of the future. The Two-on-Two model was used for determination of scenarios...
متن کاملImage flip CAPTCHA
The massive and automated access to Web resources through robots has made it essential for Web service providers to make some conclusion about whether the "user" is a human or a robot. A Human Interaction Proof (HIP) like Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) offers a way to make such a distinction. CAPTCHA is a reverse Turing test used by Web serv...
متن کاملFuture Scenarios of Iran's Public Libraries Based on Futures Workshops for Selected Librarians, Managers and Members
Purpose: Nowadays, public libraries are going through a critical period and turning point, a time when from one hand and based on the environmental trends affecting them, can be a sign of their future elimination, or on the other hand if they enjoy an accurate picture of the future and adopt appropriate strategies, can provide them with a renewed vital opportunity. This issue is related to the ...
متن کاملSemantic Authorization of Mobile Web Services
With the recent developments in the cellular world, the high-end mobile phones and PDAs are becoming pervasive and are being used in different application domains. Integration of the web services and cellular domains lead to the new application domain, mobile web services. Mobile web service provisioning offers many of its applications in domains like e-commerce, collaborative applications, soc...
متن کاملAdaptive Information Analysis in Higher Education Institutes
Information integration plays an important role in academic environments since it provides a comprehensive view of education data and enables mangers to analyze and evaluate the effectiveness of education processes. However, the problem in the traditional information integration is the lack of personalization due to weak information resource or unavailability of analysis functionality. In this ...
متن کامل