Securing web services

  • Authors:
  • M. Hondo;N. Nagaratnam;A. Nadalin

  • Affiliations:
  • IBM Software Group, Cambridge, Massachusetts;IBM Application&Integration Middleware Division, Raleigh, North Carolina;IBM Software Group, Austin, Texas

  • Venue:
  • IBM Systems Journal
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

The Web service security challenge is to understand and assess the risk involved in securing a Web-based service today, based on our existing security technology, and at the same time track emerging standards and understand how they will be used to offset the risk in new Web services. Any security model must illustrate how data can flow through an application and network topology to meet the requirements defined by the business without exposing the data to undue risk. In this paper we propose a mechanism for the client to provide authentication data, based on the service definition, and for the service provider to retrieve those data. We also show how XML Digital Signatures and encryption can be exploited to achieve a level of trust.