Profiles for conveying the secure communication requirements of Web services

被引:1
作者
Merrill, Duane [1 ]
Grimshaw, Andrew [1 ]
机构
[1] Univ Virginia, Dept Comp Sci, Charlottesville, VA 22903 USA
关键词
Web services; security; interoperability;
D O I
10.1002/cpe.1403
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
A fundamental theme of the services-oriented Grid paradigm is the collaboration of participants from different administrative and security domains. As such, constructing meaningful, interoperable security that brokers interorganizational trust as well as token syntax and semantics is crucial for fostering Grid adoption and buy-in. This is a lofty goal that must be tackled together by standards communities, middleware and platform software architects, and domain administrators. A crucial first step toward realizing this goal is the ability to normatively describe the secure communication requirements that affect message format. As such, we present two new OGF security profiles that provide guidance for the expression and conveyance of secure communication requirements. The Secure Communication Profile 1.0 is a refinement of the WS-SecurityPolicy specification. The goals of this profile are to impose more restrictive conformance requirements on the WS-Security mechanisms described by WS-SecurityPolicy assertions, to facilitate key distribution and policy timestamping, and to profile normative 'well-known' policy documents that identify commonly used security mechanisms. The Secure Addressing Profile 1.0 refines the WS-Addressing specification in order to profile the inclusion of security policy within endpoint references (EPRs). This approach of conveying security policy within EPRs is well suited to the Grid paradigms of stateful Web service resources and factory patterns. Copyright (C) 2009 John Wiley & Sons, Ltd.
引用
收藏
页码:991 / 1011
页数:21
相关论文
共 33 条
  • [1] [Anonymous], WS TRUST 1 3
  • [2] [Anonymous], 2005, ASS PROT OASIS SEC A
  • [3] [Anonymous], WEB SERV SEC SOAP ME
  • [4] [Anonymous], 2246 IETF RFC
  • [5] AUDUN J, 2005, P 2005 AUSTR WORKSH, V44
  • [6] Del Vecchio D, 2005, 2005 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, VOLS 1 AND 2, PROCEEDINGS, P149
  • [7] FOSTER I, 2007, 108 GFD OP GRID FOR
  • [8] GRIMSHAW A, 2007, 109 OP GRID FOR GFD
  • [9] Hapner M., 2002, JAVA MESSAGE SERVICE
  • [10] *IBM, 2008, IBM WEBSPH MQ