Scalable security description framework for mobile Web services
M. Morioka, Yoshifumi Yonemoto, Toshihiro Suzuki, Minoru Etoh · 2004
We propose a scalable security description framework for mobile Web services that takes account of service context such as time constraints, purchase prices, and network connection status. We also present a secure open interface for multi-level authorization procedures. To describe AAA service flows, the framework adopts the Web service flow language (WSFL) and the Web service description language (WSDL); it uses the security assertion markup language (SAML) to describe security certificates. We extend WSDL so that it offers security attributes that specify the underlying secure protocols. Combining WSFL, WSDL, SAML, and service context descriptions yields scalable AAA services that will support mobile e-commerce by realizing high-speed and effective micropayments.