Securing XML Web Services : using WS-security
Martin Antonsson · Diva portal (Dalarna University Library) · 2003
The technology XML Web Services builds upon that data is transferred on a network like the Internet. It usually occurs behind firewalls. It is in the communication between parties involved where problem arise. HTTP in combination with SSL for instance can only guarantee the security from one point to another, but when XML Web Services come into the picture the communication is often more complex. The data is embedded in a SOAP message and it can be sent over several transport protocols, not only HTTP. SMTP is one of them. The data may also travel between multiple intermediaries and this topology demands a way to secure the complete communication, end-to-end. If a company adopts an implementation of WSSecurity the security in the communication could be guaranteed end-to-end. WS-Security is a specification designed to be flexible. It specifies using existing standards and techniques for securing the message’s confidentiality and integrity. For this, WS-Security endorses to use XML Encryption and XML Signature respectively. It also supports multiple security tokens that can be used to authenticate the end user. This master thesis describes one implementation of WS-Security. The implementation is conducted at Fishbone Systems AB. If they apply this project’s implementation, their XML Web Services will be secured.