PWSSec: Process for Web Services Security

  • Authors:
  • C. Gutierrez;E. Fernandez-Medina;M. Piattini

  • Affiliations:
  • STL, Madrid, Spain;Alarcos Research Group. Universidad de Castilla-La Mancha.;Alarcos Research Group. Universidad de Castilla-La Mancha.

  • Venue:
  • ICWS '06 Proceedings of the IEEE International Conference on Web Services
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

In the last few years, the field of Web Services (WS) security has evolved rapidly producing an impressive number of WS-based security standards. This fact has caused that organizations are still reticent about adopting technologies based on this paradigm due to the learning curve necessary to integrate security into their practical deployments. In this paper, we present PWSSec (Process for Web Services Security) as a process that enables the integration of a set of specific stages into the traditional phases of WS-based systems development providing them with security. PWSSec is composed of three stages, WSSecReq (Web Services Security Requirements), WSSecArch (Web Services Security Architecture) and WSSecTech (Web Services Security Technologies) that allow the specification of WS-specific security requirements, the definition of the WS-based security architecture and the identification of the security standards that the security architecture must deploy, respectively.