Font Size: a A A

Outline Design, Based On The Ws Security E-commerce Web Services Security

Posted on:2004-04-01Degree:MasterType:Thesis
Country:ChinaCandidate:F F KongFull Text:PDF
GTID:2208360092480095Subject:Computer application technology
Abstract/Summary:PDF Full Text Request
E-Business as an application of network, its information is transformed in the Internet digital. So freedom and open in the Internet brought security hidden trouble to the E-Business application. In E-Business, security is vital business. Security solution for end to end application is required; it includes encryption, digital signatures, Security management, firewall and so on. This is very different form tradition business. This paper the specification that proposes a standard set of SOAP extensions that can be used when building secure Web services to implement integrity and confidentiality. We refer to this set of extensions as the "Web Services Security Language" or "WS-Security".This paper discusses the standard set of SOAP and its security system, and status and technology of current E-Business. In this chapter, two security protocol SSL (Secure Socket Layer) and SET (Secure Electronic Transaction) are introduced, at same time the two protocol are analyzed and compared. On the basis of standard, the paper brings forward and analyses security system architecture base on WS-Security, and expounds its key technology Security Token, XML Encryption and XML Signature.WS-Security uses SOAP header to carry security message. If uses XML Signature, this header should embody the message defined of XML Signature, which includes signature methods, using key and signature value. If some elements use XML encryption, the header should embody the message defined of XML Encryption. WS-Security not restricts the format of XML Encryption or XML Signature, but restricts how to embed some message defined by other standards. WS-Security is mostly a standard using XML security elements container. In the SOAP header, message can be used saved the information of call direction, signature method and encryption method. WS-Security saves total security information into SOAP header of the message, so it can provide end to end security solution for security of web service.In this paper, we can learn how to use WS-Security and other methods to embed security mechanism into SOAP message. We can understand identity validate, Signature and Encryption of WS-Security. The paper analyses how to design and realize the web service security system architecture base on WS-Security, and discuss application of some parts' function. The paper using sample explain the architecture and function of web service security system architecture, show the Security token, XML Encryption and XML Signature.Finally, the paper summarizes the content, does some analyses and prospect of web service security application.
Keywords/Search Tags:E-business, WS-Security, web security applcation, SOAP, XML Encryption, XML Signature
PDF Full Text Request
Related items