Dynamic and Ubiquitous Security Architecture for Global SOA
Deven Shah, Dhiren Patel · 2008
Web services burst into the scene in 1998, with all the fanfare of "loosely coupled". For all its proponents, it has enjoyed only limited adoption within the enterprise. Enter Web 2.0 - the social revolution of the Internet. This duo, going by the moniker 'Global SOA', can turn enterprise wide web services for the end-user. Web Services Security Specification (WS-Security - OASIS) provides a set of mechanisms to help developers of Web Services secure SOAP message exchanges in enterprise environment. But it is not ubiquitous for Global SOA as offered by SSL for current Internet applications. This paper gives a detailed analysis of the security requirements for Global SOA and proposes a solution for ubiquitous usage. Our strategy is to work on SOAP message interceptor (Handler using WS-Security specification) for providing message level security. For Global SOA, We are proposing architecture for ubiquitous integration of security using handlers without any pre-configuration required at service requester side.