Integrated Security Context Management of Web Components and Services in Federated Identity Environments

被引:0
|
作者
Kumar, Apurva [1 ]
机构
[1] IBM Corp, India Res Lab, C Vasant Kunj Inst Area, New Delhi 110070, India
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The problem of providing unified web security management in,in environment with multiple autonomous security domains is considered. Security vendors provide separate security management solutions for cross-domain browser based and web service based interactions. This is partly due to the fact that different web standards dominate in each space. E.g. Security Assertion Markup Language (SAML) which is an important standard in cross domain single sign on (SSO) specializes in browser based access while WS-* standards focus on security needs of web services. However, cross domain web services are often invoked in context of a Secure browser session. Considering these interactions in isolation will lead to a fractured security solution. This paper proposes a solution that provides seamless transfer of security context across various types of cross-domain web interactions.
引用
收藏
页码:565 / 571
页数:7
相关论文
共 50 条
  • [1] Notarized federated identity management for web services
    Goodrich, Michael T.
    Tamassia, Roberto
    Yao, Danfeng
    DATA AND APPLICATIONS SECURITY XX, PROCEEDINGS, 2006, 4127 : 133 - 147
  • [2] Using web services to exchange security tokens for federated trust management
    Wu, Zhengping
    Weaver, Alfred C.
    2007 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2007, : 1176 - +
  • [3] Federated Management: Toward Federated Services and Federated Security in Federated Ecology
    Wang, Fei-Yue
    Qin, Rui
    Li, Juanjuan
    Wang, Xiao
    Qi, Hongwei
    Jia, Xiaofeng
    Hu, Bin
    IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2021, 8 (06): : 1283 - 1290
  • [4] A Survey of Security Analysis in Federated Identity Management
    Simpson, Sean
    Gross, Thomas
    PRIVACY AND IDENTITY MANAGEMENT: FACING UP TO NEXT STEPS, 2016, 498 : 231 - 247
  • [5] Mapping Web Services Standards to Federated Identity Management Requirements for m-Health
    Liu, Hui
    Li, Ming-lu
    Lin, Xin
    ICICSE: 2008 INTERNATIONAL CONFERENCE ON INTERNET COMPUTING IN SCIENCE AND ENGINEERING, PROCEEDINGS, 2008, : 459 - +
  • [6] Federated security: Lightweight security infrastructure for object repositories and Web Services
    Hatala, M
    Eap, TM
    Shah, A
    INTERNATIONAL CONFERENCE ON NEXT GENERATION WEB SERVICES PRACTICES, 2005, : 287 - 292
  • [7] Security management of web services
    Malek, M
    Harmantzis, F
    NOMS 2004: IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, APPLICATION SESSIONS: MANAGING NEXT GENERATION CONVERGENCE NETWORKS AND SERVICES, 2004, : 175 - 189
  • [8] Federated Identity Management as a Basis for Integrated Information Management
    Schell, Frank
    Hoellrigl, Thorsten
    Hartenstein, Hannes
    IT-INFORMATION TECHNOLOGY, 2009, 51 (01): : 14 - 23
  • [9] Integrated Security for Services Hosted in Virtual Environments
    Jayarathna, Dilshan
    Varadharajan, Vijay
    Tupakula, Udaya
    2016 IEEE TRUSTCOM/BIGDATASE/ISPA, 2016, : 82 - 89
  • [10] Integrated Security Framework for Secure Web Services
    Zhang, Wenjun
    2010 THIRD INTERNATIONAL SYMPOSIUM ON INTELLIGENT INFORMATION TECHNOLOGY AND SECURITY INFORMATICS (IITSI 2010), 2010, : 178 - 183