Best-Practice Patterns and Tool Support for Configuring Secure Web Services Messaging

  • Authors:
  • Michiaki Tatsubori;Takeshi Imamura;Yuhichi Nakamura

  • Affiliations:
  • IBM Tokyo Research Laboratory;IBM Tokyo Research Laboratory;IBM Tokyo Research Laboratory

  • Venue:
  • ICWS '04 Proceedings of the IEEE International Conference on Web Services
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents an emerging tool for securityconfiguration of service-oriented architectures with WebServices. Security is a major concern when implementingmission-critical business transactions and such concernmotivated the development of Web Services Security(WS-Security). However, the existing tools for configuringthe security properties of Web Services give atechnology-oriented view, and only assist in choosingthe data to encrypt and selecting an encryption algorithm.The users must construct their own mental modelsof how the security configurations actually relate tobusiness policies.In contrast, the tool described here gives a simplified,business-policy-oriented view. It models the messagingwith customers and business partners, lists variousthreats, and presents best-practice security patternsagainst the threats. A user can select among variationson the basic patterns according to the business policies,and then apply them to the messaging model through theGUI. The result of the pattern application is describedin the Web Services Security Policy Language (WS-SecurityPolicy).