首页> 外文会议>ACM workshop on Secure web services >Towards secure SOAP message exchange in a SOA
【24h】

Towards secure SOAP message exchange in a SOA

机译:在SOA中迈向安全的SOAP消息交换

获取原文

摘要

SOAP message exchange is one of the core services required for system integration in Service Oriented Architecture (SOA) environments. One key concern in a SOA is thus to provide Message Level Security (as opposed to point to point security). We observe that systems are communicating with each other in a SOA over SOAP messages, often without adequate protection against XML rewriting attacks.We have already provided a solution to protect the integrity of SOAP messages in earlier work [1]. This solution was based on the usage of messagestructure information (SOAP Account) for preservation of message integrity. However, this earlier work did not discuss the issue of forging the SOAP Account itself. In this paper, we discuss the integrity feature of a SOAP Account within a more general context of the current web service security state of the art.
机译:SOAP消息交换是服务导向体系结构(SOA)环境中系统集成所需的核心服务之一。因此,SOA中的一个关键问题是提供消息级安全性(而不是指向点安全性)。我们观察到系统在SOA上彼此在SOA上互相通信,通常没有足够的防止XML重写攻击。我们已经提供了解决方案来保护早期工作中的SOAP消息的完整性[1]。此解决方案基于MessageStructure信息(SOAP帐户)的使用来保存消息完整性。然而,这个早期的工作没有讨论锻造肥皂账户本身的问题。在本文中,我们讨论了在当前Web服务安全状态的更一般背景下的SOAP帐户的完整性特征。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号