摘要
为了解决目前主流的基于WS-security的面向服务安全框架中的安全脆弱性问题,保证面向服务架构中Web服务的安全,通过采用将安全语句封装在SAML断言语句块中,创建SAML认证声明及进行SAML授权等为服务响应模块提供安全断言,并通过网络层和服务层的安全实现来保证Web服务的安全和实现用户的单点登录等。
In order to solve the safety vulnerability problems of the mainstream SOA Security framework based on the WS-security,ensure the security of service in the service oriented architecture,the author put forward the secure model of service oriented archtecture framework based on the security assertion markup language,mainly focusing on the network layer and service layer security to build the SOA security solution,specifically through encapsulating the secutiry assertion into the SAML assertion statement,creating SAML secure statement and promising the secure of SAML authentication for the service provider to ensure the security of web services in SOA and achieve the user's single sign on.etc.
出处
《浙江理工大学学报(自然科学版)》
2011年第4期631-637,共7页
Journal of Zhejiang Sci-Tech University(Natural Sciences)
关键词
面向服务架构模型
安全断言标记
单点登录
service-oriented architecture model of security
security assertion markup language
single sign on