• DocumentCode
    1178460
  • Title

    Standards for XML and Web services security

  • Author

    Naedele, Martin

  • Author_Institution
    ABB Corporate Res., Switzerland
  • Volume
    36
  • Issue
    4
  • fYear
    2003
  • fDate
    4/1/2003 12:00:00 AM
  • Firstpage
    96
  • Lastpage
    98
  • Abstract
    XML schemas convey the data syntax and semantics for various application domains, such as business-to-business transactions, medical records, and production status reports. However, these schemas seldom address security issues, which can lead to a worst-case scenario of systems and protocols with no security at all. At best, they confine security to transport level mechanisms such as secure sockets layer (SSL). On the other hand, the omission of security provisions from domain schemas opens the way for generic security specifications based on XML document and grammar extensions. These specifications are orthogonal to domain schemas but integrate with them to support a variety of security objectives, such as confidentiality, integrity, and access control. In 2002, several specifications progressed toward providing a comprehensive standards framework for secure XML-based applications. The paper shows some of the most important specifications, the issues they address, and their dependencies.
  • Keywords
    Internet; data privacy; hypermedia markup languages; security of data; software standards; Security Assertion Markup Language; Web services security; XML; access control; data confidentiality; data integrity; domain schemas; grammar; secure sockets layer; standards; transport level mechanisms; Access control; Access protocols; Authentication; Markup languages; Permission; Public key; Security; Simple object access protocol; Web services; XML;
  • fLanguage
    English
  • Journal_Title
    Computer
  • Publisher
    ieee
  • ISSN
    0018-9162
  • Type

    jour

  • DOI
    10.1109/MC.2003.1193234
  • Filename
    1193234