摘要
企业信息系统在发展过程中逐渐具有跨域、跨互联网等性质,其结构日益复杂,同时企业数据的机密性又对信息系统的业务运行过程提出了更高的安全需求。目前对于采用SOA进行架构的信息系统尚没有正式的国际安全标准和规范,通过对企业环境下的Web Service安全技术,如传输层安全和SOAP安全、数字签名和断言等进行研究,以J2EE架构下的企业环境为例,提供了一种通过结合企业安全服务和综合应用层、传输层安全技术来保障企业信息系统整体安全性、可靠性的可行思路。
The enterprise information system nowadays is largely domain-cross and Internet-cross,and is constructed with unprecedented complexity.Meanwhile the confidentiality of enterprise data requires the business process to be more secure than before.However,there exists no official standard and specification for SOA-architected information systems.Based on investigation of security technologies for Web services such as transport layer security,SOAP security,digital signature and assertions under enterprise environments,and with J2EE-architected enterprise environment as an example,a method in combining enterprise security services together with application/transport level security measures,for assuring enterprise information security and the method is proved applicable.
出处
《通信技术》
2011年第5期48-51,共4页
Communications Technology