首页> 外文会议>ACM workshop on Secure web services >Towards secure SOAP message exchange in a SOA
【24h】

Towards secure SOAP message exchange in a SOA

机译:在SOA中实现安全SOAP消息交换

获取原文

摘要

SOAP message exchange is one of the core services required for system integration in Service Oriented Architecture (SOA) environments. One key concern in a SOA is thus to provide Message Level Security (as opposed to point to point security). We observe that systems are communicating with each other in a SOA over SOAP messages, often without adequate protection against XML rewriting attacks.We have already provided a solution to protect the integrity of SOAP messages in earlier work [1]. This solution was based on the usage of messagestructure information (SOAP Account) for preservation of message integrity. However, this earlier work did not discuss the issue of forging the SOAP Account itself. In this paper, we discuss the integrity feature of a SOAP Account within a more general context of the current web service security state of the art.
机译:SOAP消息交换是面向服务的体系结构(SOA)环境中系统集成所需的核心服务之一。因此,SOA中的一个关键问题是提供消息级别安全性(与点对点安全性相对)。我们注意到,系统之间在SOA上通过SOAP消息进行通信,通常没有足够的防护以防止XML重写攻击。我们已经提供了一种解决方案,可以在早期工作中保护SOAP消息的完整性[1]。此解决方案基于消息结构信息(SOAP帐户)的使用,以保持消息的完整性。但是,此较早的工作并未讨论伪造SOAP帐户本身的问题。在本文中,我们将在当前Web服务安全性的更一般背景下讨论SOAP帐户的完整性功能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号