节点文献

基于可信SOAP的Web Services安全架构的实现

The Implementation of Web Services Security Architecture Based on Trust SOAP

【作者】 周颖

【导师】 刘泉;

【作者基本信息】 武汉理工大学 , 通信与信息系统, 2004, 硕士

【摘要】 随着Web服务的不断发展,不可避免地存在着由此所带来的信息安全隐患。因此在Web服务中,安全性成为一个至关重要的核心问题,它要求网络能提供一种端到端的安全解决方案,如加密机制、签名机制、安全管理、存取控制、防火墙、防病毒保护等等。SOAP作为Web服务通信协议的基础,在实现Web服务安全性的工程中扮演着及其重要的角色。 本文研究了Web服务安全规范WS-Security的内容和架构:Web服务安全性语言(Web Services Security Language)是一个建立在标准的SOAP标准规范上,可以在构建安全的Web服务以实现完整性和机密性时使用的安全规范。WS-Security定义了一个用于携带安全性相关数据的SOAP标头元素。如果使用XML签名,此标头可以包含由XML签名定义的信息,其中包括消息的签名方法、使用的密钥以及得出的签名值。同样,如果消息中的某个元素被加密,则WS-Security标头中还可以包含加密信息(例如由XML加密定义的加密信息)。WS-Security并不指定签名或加密的格式,而是指定如何在SOAP消息中嵌入由其他规范定义的安全性信息。WS-Security主要是一个用于基于XML的安全性元数据容器的规范。在此标头中,消息可以存储关于调用方、消息的签名方法和加密方法的信息。WS-Security将所有安全信息保存在消息的SOAP部分中,从而为Web服务安全性提供了端到端的解决方案。 本文在WS-Security架构的实现中,介绍了SOAP标准规范及相应的安全机制,并讨论了Web Service安全上的现状以及现有安全解决方案存在的问题。本文研究介绍了WS-Security所涉及的三个方面:身份验证、签名和加密,并提出了如何使用WS-Security和其他配合工具WSE在SOAP消息中嵌入安全机制。在Web服务安全规范WS-Security的基础上,提出并分析了新的可信SOAP安全性模型的体系架构设计的基本原理并阐明了它的优点,对安全规范的关键技术——XML签名机制与XML加密机制也做了详细阐述。最后,本文遵循WS-Security的思想,使用现有的安全技术设计与实现了一个基于可信SOAP安全性模型的WS-Security架构,并对各部分的功能及实现机制作了详细介绍,详细分析了XML签名机制与XML加密机制。

【Abstract】 With the development of Web service, it is inevitable to bring security hidden trouble to the information. So its security is becoming more and more important to Web service. Security solution for end to end application is required; it includes encryption, digital signatures, Security management, firewall and so on. SOAP, the basis of Web Service transport protocol, plays an important role in the implementation of Web Services Security.This paper introduces the specification that proposes a standard set of SOAP extensions that can be used when building secure Web services to implement integrity and confidential. We refer to this set of extensions as the "Web Services Security Language" or "WS-Security". WS-Security uses SOAP header to carry security message. If uses XML Signature, this header should embody the message defined of XML Signature, which includes signature methods, using key and signature value. If some elements use XML encryption, the header should embody the message defined of XML Encryption. WS-Security not restricts the format of XML Encryption or XML Signature, but restricts how to embed some message defined by other standards. WS-Security is mostly a standard using XML security elements container. In the SOAP header, message can be used saved the information of call direction, signature method and encryption method. WS-Security saves total security information into SOAP header of the message, so it can provide end to end security solution for security of Web Services.In this thesis we discuss the standard set of SOAP and its security system, and status and limitation existing in current solution of Web Services Security. In this paper, we can learn how to use WS-Security and other methods WSE to embed security mechanism into SOAP message. We can understand identity validate, Signature and Encryption of WS-Security. On the basis of standard, the paper brings forward and analyses the principle of Trust SOAP security system architecture, and expounds the key technology Security Token, XML Encryption and XML Signature of WS Security. Inspired by WS Security design thought, the paper tried to utilizeavailable security technologies to design and realize the WS Security system architecture base on Trust SOAP, and, explains the implementation of every part’s function, especially of XML Signature and XML Encryption.

  • 【分类号】TP393.08
  • 【被引频次】19
  • 【下载频次】408
节点文献中: 

本文链接的文献网络图示:

本文的引文网络