A Flexible and Secure Web Service Architectural Model Based on PKI and Agent Technology
Maher Ali Khemakhem, Wiem Rekik, Jacques Fayolle · International Journal for Infonomics · 2010
Web services (WS) are considered amongst the most successful and convenient way which can take the advantages of the Internet in a flexible and reusable manner.WS constitute now the corner stone of any exchanged transaction over the Internet between any given organizations or more specifically between a client and a provider.Unfortunately, despite the considerable efforts made by researchers of this field in the recent years, security and flexibility of WS still constitute a big challenge.So far WS and the corresponding providers' URLs are, indeed, advertised on specific UDDIs (Universal Description, Discovery and Integration) where the only role to be achieved is limited to the advertisement.As such, after finding the requested service any given client contacts the right provider to negotiate the service access procedure.These first contacts between clients and providers are usually unprotected (not Encrypted) yielding enough room for Hackers to intrude into these unprotected messages.To solve this problem, we proposed in our previous study [12] a new idea based on the utilization of PKI and the improvement of the UDDI which must play in addition to its initial missions the role of a trust centre lading, thus, to secure WS.In this paper, we pursue our study by attempting to solve also the flexibility problem of WS by using agent technology.More specifically, we are concerned by the flexibility that allows to any given provided WS to be used in different ways (several possibilities of composition with other WS to achieve several missions) by a given client within a fixed delay with a single contract.