A secure web services providing framework based on lock-keeper

  • Authors:
  • Feng Cheng;Michael Menzel;Christoph Meinel

  • Affiliations:
  • Hasso-Plattner-Institute, University of Potsdam, Potsdam, Germany;Hasso-Plattner-Institute, University of Potsdam, Potsdam, Germany;Hasso-Plattner-Institute, University of Potsdam, Potsdam, Germany

  • Venue:
  • APNOMS'07 Proceedings of the 10th Asia-Pacific conference on Network Operations and Management Symposium: managing next generation networks and services
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

A general model for securing widely deployed Web Services has been recommended in which the security of Web Services is divided into three layers: network security, host security and the security of Web Service message, also called SOAP message security. According to principles of this model, we propose a new secure Web Services Providing Framework based on the Lock-Keeper technology, which is a high level security solution implementing the basic security concept, "Physical Separation". In the proposed framework, the internal Web Services provider and its network are protected well by being physically isolated with the external world. At the same time, trusted Web Service message based communications can be performed smoothly and securely with the guard of a "SOAP Verification Module", which is integrated in the Lock-Keeper system. The SOAP Verification Module realizes general functionalities of both "Trust Management" and "Threat Prevention" that have been specified by most common WS-Security standards. Experiments demonstrated in this paper show that our proposed framework, which can simultaneously guarantee all the three layers of Web Services security, is feasible, applicable and secure.