Two Patterns for Web Services Security.
Eduardo B. Fernández · 2004
Patterns are widely used in software engineering where they have been successful in improving analysis and design by encapsulating the experience of many designers. Security patterns are a recent development as a way to encapsulate the accumulated knowledge about secure systems design. We present here two patterns for web services: 1) a Security Assertion Coordination pattern that coordinates authentication and authorization using a Role-Based Control (RBAC) model for access to distributed resources; and 2) A pattern for XML firewalls, that filters XML messages or documents according to institution policies. Because of space restrictions we only describe some sections of the standard template descriptions; more details can be seen in [1] and [7]. Keywords: Distributed systems security, Object-oriented patterns, SAML, Security patterns, XML firewalls Web services are increasing in importance but one of the main obstacles to their acceptance is security. This situation is improving with the appearance of several security standards that define architectural requirements to provide appropriate levels of security [2]. One of these standards is the Security Assertion Markup Language (SAML), that expresses security assertions that can be exchanged between nodes in a