A Web service authentication control system based on SRP and SAML
Flávio de Oliveira Silva, J.A.A. Pacheco, Pedro Frosi Rosa · 2005
Actually Internet applications can provide not only information, but also, another way of getting distributed computing. Cooperative information systems are autonomous and heterogeneous systems, distributed geographically, but interconnected. Web Services provides a set of interoperable standards that can be used to connect distributed applications. On this environment, security is a critical issue, and an attack can expose systems services without authentication. An end-to-end connection, like the ones involved in such systems, usually requires that an authentication can be shared between different information systems. Web Services security model is not yet fully defined and a lot of proposals are emerging, delaying the adoption of this technology in many situations. In this paper we present multiplatform authentication control system based on an extension of SRP protocol, using SAML. Within this solution, authentication control can be leveraged, even with weak passwords and an authentication assertion can be exchanged with different cooperative information systems.