【24h】

HTTPI Based Web Service Security over SOAP

机译:SOAP上基于HTTPI的Web服务安全性

获取原文
           

摘要

Now a days, a new family of web applications 'open applications’, are emerging (e.g., Social Networking, News and Blogging). Generally, these open applications are non-confidential. The security needs of these applications are only client/server authentication and data integrity. For securing these open applications, effectively and efficiently, HTTPI, a new transport protocol is proposed, which ensures the entire security requirements of open applications. Benefit of using the HTTPI is that it is economical in use, well-suited for cache proxies, like HTTP is, and provides security against many Internet attacks (Server Impersonation and Message Modification) like HTTPS does. In terms of performance HTTPI is very close to the HTTP, but much better than HTTPS. A Web service is a method of communication between two ends over the Internet. These web services are developed over XML and HTTP. Today, most of the open applications use web services for most of their operations. For securing these web services, security design based on HTTPI is proposed. Our work involves securing the web services over SOAP, based on the HTTPI. This secure web service might be applicable for open applications, where authentication and integrity is needed, but no confidentiality required. In our paper, we introduce a web service security model based on HTTPI protocol over SOAP and develop a preliminary implementation of this model. We also analyze the performance of our approach through an experiment and show that our proposed approach provides higher throughput, lower average response time and lower response size than HTTPS based web service security approach
机译:如今,新的网络应用程序系列“开放式应用程序”正在涌现(例如,社交网络,新闻和博客)。通常,这些打开的应用程序是非机密的。这些应用程序的安全需求仅是客户端/服务器身份验证和数据完整性。为了有效有效地保护这些开放应用程序的安全,HTTPI提出了一种新的传输协议,该协议可确保开放应用程序的全部安全要求。使用HTTPI的好处是它使用起来很经济,像HTTP一样非常适合缓存代理,并且像HTTPS一样提供了针对许多Internet攻击(服务器模拟和消息修改)的安全性。在性能方面,HTTPI非常接近HTTP,但比HTTPS好得多。 Web服务是通过Internet在两端之间进行通信的一种方法。这些Web服务是通过XML和HTTP开发的。如今,大多数打开的应用程序都将Web服务用于大多数操作。为了保护这些Web服务,提出了基于HTTPI的安全设计。我们的工作涉及基于HTTPI通过SOAP保护Web服务。此安全的Web服务可能适用于需要身份验证和完整性但不需要机密性的开放应用程序。在本文中,我们介绍了基于SOAP上基于HTTPI协议的Web服务安全性模型,并开发了该模型的初步实现。我们还通过实验分析了该方法的性能,并表明与基于HTTPS的Web服务安全性方法相比,我们提出的方法可提供更高的吞吐量,更低的平均响应时间和更小的响应大小。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号