Developing a Web Service Security Framework

Yangil Park, Jeng-Chung Chen · IGI Global eBooks · 2009

Web Service (WS) is an open standard software component that uses Extensible Markup Language (XML) functions to access and exchange data via networks in communicating with other WSs. In business transactions, Web Service Description Language (WSDL) is used to describe data and deliver all parameters, return values, and types. However, the convenience of using WSDL in business transactions also lets hackers snoop and analyze data easily. In addition, the lack of Web Service standards at present makes the security issue even more serious in business transactions using WS. This article proposes a high-level security model for the security problems of the applications. Unlike other studies in the field, this study is dedicated to provide a total solution consisting of technological, organizational, and managerial aspects when using WS. Therefore, the understanding and development of business behaviors is essential in this study. It first introduces current uses of WS. Then definitions of WS, WS security, and WS policy are reviewed. Finally, a WS security model is proposed and explained in the following examples.

Read the paper · More papers on PaperTik