节点文献

Web服务加密与签名技术研究

【作者】 安之廷

【导师】 王占杰;

【作者基本信息】 大连理工大学 , 计算机应用, 2003, 硕士

【摘要】 Web服务是一种新型的组件技术,从其概念的提出到现在,历经了不到三年的时间,然而已经对基于Web的应用程序设计、开发和部署带来了巨大的影响。它构建在一系列协议的基础之上,具有松耦合、平台无关、语言无关、设备无关等特性,在企业应用集成和电子商务领域拥有巨大的发展潜力。但在把Web服务投入商业应用过程中,服务信息的安全传递问题一直没有得到有效的解决,如何实现具有一定通用性的安全机制成为目前研究的重点。 本文对Web服务运行机理进行了研究,说明了Web服务中基本角色之间的关系与操作,着重分析了服务调用过程中所使用的简单对象访问协议(SOAP)。该协议是一种基于XML的简单协议,用于在Web上交换结构化的数据和类型信息。在请求与响应过程中,SOAP消息中可能会包含用户的敏感信息,需要采取措施保证其安全性。由于协议本身没有定义处理安全信息的方法,因此本文依靠SOAP扩展来加入自定义的安全信息。为了保证对SOAP扩展的处理具有通用性,本文根据W3C的XML加密和签名的相关规范,剖析了对XML文档进行加密和签名的原理、需要生成的必要元素以及元素之间的语义关系。最后,本文说明了如何把这些加密和签名元素存放到SOAP消息中,并使用WSDK实现了一个基于过滤机制的安全Web服务的实例,保证了服务请求与响应信息的机密性、完整性,满足了对身份认证和不可抵赖性的需求。

【Abstract】 Web Service is a new type of component technology not more than three years’ old from the first time its concept was brought out. It has big impact on the method of application designing, developing and deploying. Based on a series of protocols, it is featured for loose couple, platform independent, language independent and device independent. It has showed great potential in fields of Enterprise Application Integration (EAI) and E-business. When putting web service into business application, the problem of how to secure the delivering message is still unsolved. Current studies focus on how to build a unified security solution.This article studies the working theory of Web Service, explains the relationship and actions between SOAP roles. Then it focuses on the structure of SOAP message used during a service invoking. It is a simple protocol base on XML, used to transmit the structured information and type information. During a Web service invoking, the SOAP message may contain secret information, and should take measure to ensure it. But the protocol does not define the method of how to deal with security information. So this article uses SOAP extension to add customized security information. In order to make this information unified, this article illustrates how to encrypt and sign a SOAP message according to the XML encryption and signature standard of W3C. It also demonstrates the necessary XML elements and the semantic relationship between the elements. Finally, this article illustrates how to add the security information into a SOAP message and implements a secured Web Service example with WSDK based on filter model. It fulfills the requirements of confidentiality, security, authentication and non-reputation.

  • 【分类号】TP393.08
  • 【被引频次】4
  • 【下载频次】199
节点文献中: 

本文链接的文献网络图示:

本文的引文网络