Designing A Secure Integration Model For EGovernance Platforms
Paulus Shigwedha, Fungai Bhunu Shava · 2021
E-governance has become an important element of good governance in Namibia and elsewhere in the world. Countries including Namibia has embraced this phenomenal tool by employing e-government systems that provide, amongst other benefits, the governance, and the interoperability of external systems from various entities with a common goal. The communication in the e-governance platform and many data exchange systems alike, such as health information exchange systems, usually depends on the interoperability of the platforms achieved with platform-independent architectures and protocol such as Representational State Transfer (REST), Simple Object Access Protocol (SOAP) or Application Programming Interface (APIs), which is an important building block for developing distributed applications, published as web services over an Intranet or the Internet. However, in most interoperability or integrations of systems, the interfacing component of the integration has been regarded as the most likely to be the weak link in terms of vulnerabilities [4]. Protocols such as SOAP commonly used for web-service integration, are prone to several vulnerabilities such as SOAP Injection and WSDL disclosure/enumeration that could make SOAP powered web-service integration vulnerable if not mitigated. This paper adopts the Design Science paradigm to design a secure integration model to mitigate vulnerabilities presented by the SOAP-powered and any other web-service integration protocols, to achieve secure integrations of heterogeneous systems in e-governance platforms.