Research on Secure Web Service in Mobile E-Government Platform
Zhao Qiu · IEEE Software · 2011
In platform of mobile e-government,Web service is the most common usages in deployment plan.By reason of the Web service is self-contained and self-described and modularized,it can be invoking,it need to consider that security of the web service be used.Web service transmit data by SOAP,SOAP reformatting data in the shape of XML there are many venture in the channel,Non-encrypted soap message transmitted in an insecure channel may leak sensitive data.Data must be encryption if the data is sensitivity.In order to settle the problems in view of the foregoing,giving out a solution based on the.net platform.When use Web service,only authorized users can access to the services provided by Web services,when client log in,obtain public key first.In response to these issues:first client connect to the server,obtain the public key of server,and then negotiate with server about the asymmetric encryption key and symmetric key used for encrypting the soap,and obtained the encrypted SessionID from server.Use Soap header to achieve authentication,and use Soap extension to achieve Soap message optional encryption,ensured the security of web services.