Seamlessly Securing Web Services by a Signing Proxy

نویسندگان

  • Mario Jeckle
  • Ingo Melzer
چکیده

Web services offer a way for very different systems to collaborate independent of the programming language used or the involved operating systems. Their basis is the XML-based SOAP protocol, which can be used over any protocol that is able to transport a byte stream. Due to the fact that Web services do not depend on any operating system and there is no burden of a underlying paradigm, they are ideal for the integration of even completely inhomogeneous systems. However, SOAP does not (and does not have to) deal with security issues, which is nevertheless important for the involved systems. This article describes an add-on for existing Internet proxies to achieve user and developer transparent security features for Web services. This approach allows corporate firewalls to handle authentication. A first step is to add corporate signatures to all outgoing SOAP messages to enable a corporate trust relationship. A second improvement is to use proxy authentication as defined in RFC 2616 and RFC 2617 to add personal signatures assuming that the proxy has access to some key management system.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Securing Web Services with SOAP Security Proxies

Although in principle independent of any particular messaging protocol, Web Services are primarily accessed using SOAP over HTTP in practice. As SOAP provides no message security at all, other ways of securing messages are necessary. This paper summarizes the most important security model for SOAP, WS-Security, and its related specifications. We explore the advantages of one particular approach...

متن کامل

A Signing Proxy for Web Services Security

Web Services offer a way for very different systems to collaborate independent of the the used programming language or the involved operating systems. Their basis is the XML-based SOAP protocol which can be used over any protocol which is able to transport a byte steam. Due to the fact that Web Services do not depend on any operating system and there is no burden of a underlying paradigm, they ...

متن کامل

A SOAP-Oriented Component-Based Framework Supporting Device-Independent Multimedia Web Services

A web service is a programmable web application accessible using standard Internet protocols. A threelayer architecture has been suggested for web services: service providers, service brokers, and service requesters. We propose in this paper a SOAP-oriented componentbased framework to support device-independent multimedia web services. Two intelligent agents are introduced and embedded into pro...

متن کامل

ServiceGlobe: Flexible and Reliable Web Services on the Internet

Generic Dispatcher Service 5 ● A single service instance is not sufficient to provide low response times and high availability. ● Therefore, several instances of a service run concurrently on several hosts and our dispatcher avoids load skews performing load balancing. ● This dispatcher service (Layer-7 switch), acts as proxy for arbitrary services and is a generic solution for such situations....

متن کامل

Power Aware Hybrid Proxy Cache-Prefetch Model using Combined Energy Conservation Policies

The World Wide Web (WWW) is growing exponentially in terms of number of users and number of Web applications. Due to enormous traffic in the network and several factors like bandwidth availability, request processing time at server, round trip time and object size, the Web latency is increasing. The sophisticated integration of Web prefetching and caching deployed at proxy server with Web log m...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Int. J. Web Service Res.

دوره 1  شماره 

صفحات  -

تاریخ انتشار 2004