摘要
结合WS-Security提出了一个基于SAML和XKMS的Web服务安全模型,并引入了SOAP安全工具包的概念。通过SAML实现跨域认证和授权,通过XKMS屏蔽PKI的复杂性,实现端到端消息级传输安全。文章详细描述了SOAP工具包的工作原理,并给出了一个SOAP扩展消息实例。
Combining with WS-Security, a Web service security model based on SAML and XKMS is proposed, and the concept of SOAP security toolkits is introduced. This model implements authentication and authorization across domain by SAML, and realizes end-to-end transmission security on message-level thought shielding PKI complexity by XKMS. The working principle of SOAP toolkits is elaborated and an example of extended SOAP messages is given.
出处
《计算机时代》
2009年第12期24-26,共3页
Computer Era