【24h】

Custom Security in Web Services

机译:Web服务中的自定义安全性

获取原文
           

摘要

Background/Objectives: Service oriented Architecture (SOA) infrastructures using web services are deployed by many firms worldwide. Web Services provide a standard means of inter-operation between heterogeneous software applications that run on a variety of platforms. Most of the web services are offered with HTTP over Simple Object Access Protocol (SOAP) as the underlying infrastructure. The greatest web security threat is accepting the request from the client without proper validation. The objective is to separate the application logic and the security or validation procedures which offers more advantage for software reuse since it is not necessary to recompile, when the validation or security requirements change. Methods: An Interceptor is created for validation which has the token based authentication procedures along with the steps for validating the data. The system is devised in such a way that the business logic will be triggered if and only if the data is validated and passed by the interceptor procedures. Findings: The proposed system provides a way to keep the validation and security mechanism out of application logic and hence this does not modify the existing functionality. Thus, combining all custom security as one unit of validation before hitting the business logic is the basic idea of the proposed system.
机译:背景/目标:全球许多公司都在部署使用Web服务的面向服务的体系结构(SOA)基础结构。 Web服务提供了在各种平台上运行的异构软件应用程序之间进行互操作的标准方法。大多数Web服务都提供了基于简单对象访问协议(SOAP)的HTTP作为基础结构。最大的网络安全威胁是未经适当验证就接受来自客户端的请求。目的是将应用程序逻辑与安全性或验证过程分开,这为软件重用提供了更多优势,因为当验证或安全性要求发生变化时,无需重新编译。方法:创建了一个用于验证的拦截器,该拦截器具有基于令牌的验证过程以及验证数据的步骤。该系统的设计方式是,当且仅当数据被拦截程序验证并传递时,才触发业务逻辑。结果:所提出的系统提供了一种将验证和安全机制保持在应用程序逻辑之外的方式,因此不会修改现有功能。因此,在碰到业务逻辑之前将所有自定义安全性作为一个验证单元进行组合是所提出系统的基本思想。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号