【24h】

A Semantics for Web Services Authentication

机译:Web服务身份验证的语义

获取原文

摘要

We consider the problem of specifying and verifying cryptographic security protocols for XML web services. The security specification WS-Security describes a range of XML security tokens, such as username tokens, public-key certificates, and digital signature blocks, amounting to a flexible vocabulary for expressing protocols. To describe the syntax of these tokens, we extend the usual XML data model with symbolic representations of cryptographic values. We use predicates on this data model to describe the semantics of security tokens and of sample protocols distributed with the Microsoft WSE implementation of WS-Security. By embedding our data model within Abadi and Fournet's applied pi calculus, we formulate and prove security properties with respect to the standard Dolev-Yao threat model. Moreover, we informally discuss issues not addressed by the formal model. To the best of our knowledge, this is the first approach to the specification and verification of security protocols based on a faithful account of the XML wire format.
机译:我们考虑为XML Web服务指定和验证加密安全协议的问题。安全规范WS-Security描述了一系列XML安全令牌,例如用户名令牌,公钥证书和数字签名块,其达到用于表达协议的灵活词汇表。要描述这些令牌的语法,我们将使用密码值的符号表示扩展了通常的XML数据模型。我们在此数据模型上使用谓词来描述安全令牌的语义以及分布的示例协议,该协议与WS-Security的Microsoft WSE实现分发。通过将我们的数据模型嵌入Abadi和FourNet的应用PI微积分中,我们与标准Dolev-Yao威胁模型制定和证明安全性质。此外,我们非正式地讨论了正式模式未解决的问题。据我们所知,这是基于XML线格式的忠实账户的安全协议规范和验证的第一种方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号