AN INTEGRATED WEB SERVICES SECURITY MODEL

Chen Guilin,Zhao Shenghui,Chen Haibao,Ji Chengchao
DOI: https://doi.org/10.3969/j.issn.1000-386X.2009.02.025
2009-01-01
Abstract:Current Web services security technologies are relatively independent.However,it needs an overall security design for the whole application integrating solution.An integrated Web services security model is proposed,where the formal definition of the model and the key implementation techniques are given.The model achieves following security targets:uniform identity authentication based on certification,role-based access control and secure SOAP message transmission,which makes the model have characteristics of openness and dynamic adaptation.A prototype system is developed based on this model,the running results show that it can achieve above three secure targets,and makes the whole system more secure than single security technology.
What problem does this paper attempt to address?