期刊文献+

一种Web服务安全通信机制的研究与实现 被引量:14

Research and Implementation of a Mechanism for Web Services Secure Communications
下载PDF
导出
摘要 随着Web服务技术与应用的发展 ,Web服务安全问题日益突出 Web服务安全通信要求保证应用层SOAP消息的安全传输 ,而现有的安全传输方案 ,如SSL ,TLS等不适用于应用层的消息安全保护 ,无法满足上述要求 针对Web服务应用模式 ,提出了一种基于XML安全技术的Web服务安全通信机制 ,利用安全会话实现了较高的实体认证安全性和安全通信效率 ,并为此设计和实现了保证应用层SOAP消息安全传输的SOAPSec系统 该机制具有灵活性和可扩展性 。 With the development and application of Web services technologies, some issues of Web services security are increasingly prominent Secure communications for Web services demand secure transport of SOAP messages at application layer However, existing secure transport solutions such as SSL and TLS are not suitable for protecting message security at application layer, and cannot meet this requirement A mechanism for Web services secure communications based on XML security technologies is proposed in terms of Web services application modes Through secure session mechanism, it not only provides the identity authentication functionality with relatively high security level, but also improves the efficiency of secure communications The SOAPSec system is also designed and implemented, which ensures secure transport of SOAP messages at application layer This mechanism has the advantages of flexibility and extensibility, and can meet various requirements of secure communications in typical Web services application scenarios
出处 《计算机研究与发展》 EI CSCD 北大核心 2004年第4期679-688,共10页 Journal of Computer Research and Development
基金 国家"八六三"高技术研究发展计划基金项目(2 0 0 1AA113 0 3 0 2 0 0 1AA115 110 2 0 0 1AA414 0 2 0)
关键词 WEB服务 安全通信 SOAP WS-SECURITY 会话 Web services secure communications SOAP WS security session
  • 相关文献

参考文献11

  • 1[1]D Austin, A Barbir. W3C Web services architecture requirements. Amsterdam: W3C, 2002. http://www.w3.org/TR/2002/WD-wsa-reqs-20020819
  • 2[3]F Curbera, Y Goland. Business process execution language for Web services 1.0. New York, NY: IBM, 2002. http://www.ibm.com/developerworks/library/ws-bpel/
  • 3[4]A Brown, B Fox. SOAP security extensions: Digital signature. Amsterdam: W3C, 2001. http://www.w3.org/TR/SOAP-dsig/
  • 4[5]B Atkinson, G Della-Libera. Web services security (WS-Security), Version 1.0. Redmond, WA: Microsoft, 2002. http://msdn.microsoft.com/ws/2002/04/Security/
  • 5[6]D Eastlake, J Reagle. XML encryption syntax and processing. Amsterdam: W3C, 2002. http://www.w3.org/TR/xmlenc-core/
  • 6[8]D Eastlake, J Reagle. XML-signature syntax and processing. Amsterdam: W3C, 2002. http://www.w3.org/TR/xmldsig-core/
  • 7[9]P Hallam-Bake. XML key management specification (XKMS), Version 2.0. Amsterdam: W3C, 2003. http://www.w3.org/TR/xkms2/
  • 8[10]P Hallam-Baker, E Maler. Security assertion markup language (SAML), Version 1.0. Billerica, MA: OASIS, 2002. http://www.oasis-open.org/committees/security/docs/
  • 9[11]Trust services integration kit. Mountain View, CA: Verisign, 2002. http://www.xmltrustcenter.org/developer/verisign/tsik/index.htm
  • 10[12]Web applications and services platform (WASP), Version 4.5. Cambridge, MA: Systinet, 2003. http://www.systinet.com/products/overview

同被引文献93

引证文献14

二级引证文献51

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部