DocumentCode :
2873234
Title :
Security in SOA and Web Services
Author :
Bertino, Elisa ; Martino, Lorenzo
Author_Institution :
Purdue University
fYear :
2006
fDate :
Sept. 2006
Abstract :
Security is today a relevant requirement for any distributed application, and in particular for these enabled by the Web such as e-health, e-commerce, and e-learning. It is thus crucial that the use of Web services, stand-alone or composed, provide strong security guarantees. Web services security encompasses several requirements that can be described along the well known security dimensions, that is: integrity, whereby a message must remain unaltered during transmission; confidentiality, whereby the contents of a message cannot be viewed while in transit, except by authorized services; availability, whereby a message is promptly delivered to the intended recipient, thus ensuring that legitimate users receive the services they are entitled to. Moreover, each Web service must protect its own resources against unauthorized access. This in turn requires suitable means for: identification, whereby the recipient of a message must be able to identify the sender; authentication, whereby the recipient of a message needs to verify the claimed identity of the sender; authorization, whereby the recipient of a message needs to apply access control policies to determine whether the sender has the right to use the required resources.
Keywords :
Access control; Application software; Availability; Computer security; Distributed computing; Electronic learning; Information security; Protection; Service oriented architecture; Web services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Services Computing, 2006. SCC '06. IEEE International Conference on
Conference_Location :
Chicago, IL, USA
Print_ISBN :
0-7695-2670-5
Type :
conf
DOI :
10.1109/SCC.2006.85
Filename :
4026897
Link To Document :
بازگشت