首页> 外文OA文献 >Secure Sessions for Web Services
【2h】

Secure Sessions for Web Services

机译:Web服务的安全会话

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

We address the problem of securing sequences of SOAP messages exchanged between web services and their clients. The WS-Security standard defines basic mechanisms to secure SOAP traffic, one message at a time. For typical web services, however, using WS-Security independently for each message is rather inefficient; moreover, it is often important to secure the integrity of a whole session, as well as each message. To these ends, recent specifications provide further SOAP-level mechanisms. WS-SecureConversation defines security contexts, which can be used to secure sessions between two parties. WS-Trust specifies how security contexts are issued and obtained. We develop a semantics for the main mechanisms of WS-Trust and WS-SecureConversation, expressed as a library for TulaFale, a formal scripting language for security protocols. We model typical protocols relying on these mechanisms and automatically prove their main security properties. We also informally discuss some pitfalls and limitations of these specifications.
机译:我们解决了保护Web服务与其客户端之间交换的SOAP消息序列的安全问题。 WS-Security标准定义了用于保护SOAP流量的基本机制,一次只能发送一条消息。但是,对于典型的Web服务,为每个消息单独使用WS-Security效率很低;此外,确保整个会话以及每个消息的完整性通常很重要。为此,最近的规范提供了进一步的SOAP级机制。 WS-SecureConversation定义了安全上下文,可用于保护两方之间的会话。 WS-Trust指定如何发布和获取安全性上下文。我们为WS-Trust和WS-SecureConversation的主要机制开发了一种语义,表示为TulaFale的库,TulaFale是一种用于安全协议的正式脚本语言。我们依靠这些机制对典型协议进行建模,并自动证明其主要安全特性。我们还非正式地讨论了这些规范的一些陷阱和局限性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号