Home > SOA News > OASIS advances security standards
SOA News:
EMAIL THIS

OASIS advances security standards

By Nitin Bharti, News Editor
14 Mar 2005 | SearchWebServices.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

OASIS has made significant progress in its security standards department in recent weeks, ratifying the Extensible Access Control Markup Language (XACML) 2.0 and making strong gains with the Security Assertion Markup Language (SAML) 2.0.

XACML, which defines an XML schema for representing authorization and entitlement policies, is part of a growing portfolio of OASIS standards for security, which also include the Application Vulnerability Description Language, SAML, Service Provisioning Markup Language, Web Services (WS) Security, and the XML Common Biometric Format.

XACML 2.0 can be of particular interest to those deploying SAML, looking for a practical way to implement RBAC or protecting hierarchical resources, such as portions of XML documents.
Hal Lockhart
Senior Engineering Technologist Principal , BEA

Meanwhile, SAML 2.0 made considerable strides toward standardization as it passed a series of interoperability tests and was approved as a formal committee draft.

Although many of these standards are mutually exclusive, there are certain synergies between SAML and XACML. SAML enables the secure exchange of authentication, attribute, and authorization information across security boundaries. XACML, on the other hand, leverages this information to determine access to resources.

"There's a domain model that's shared by SAML and XACML," said Hal Lockhart, senior engineering technologist principal for BEA and co-chair of the OASIS XACML technical committee. "From XACML's point of view, there are two important entities, which are architecturally distinct: the Policy Enforcement Point (PEP) and the Policy Decision Point (PDP)."

Whereas the PEP is responsible for allowing or disallowing requests to various resources, the PDP processes the applicable policies and decides whether to grant access to the resource in question, according to Lockhart.

"The PEP makes available all the information about the request, such as who made it, when it was made, from where in the network, the resource being accessed, and potentially other kinds of information," Lockhart said. "The PDP locates the policies that apply for this particular decision and figures out the answer which the PEP then enforces."

To support users from a wide range of security environments, XACML 2.0 incorporates new profiles for Role Based Access Control (RBAC), Privacy, and Lightweight Directory Access Protocol.

"XACML 2.0 can be of particular interest to those deploying SAML, looking for a practical way to implement RBAC or protecting hierarchical resources, such as portions of XML documents," Lockhart said.

Related information

Expert advice on protecting the network from Web-based attacks

XML complexity introduces security risks

One of the powerful features of XACML is how, like SAML, it is designed to work in a federated environment consisting of disparate security systems and security policies.

"In the SAML-Liberty context you often hear about federated identity," Lockhart said. "This is what I called federated policy."

XACML is agnostic as to where a policy is obtained, according to Lockhart. In a federated environment, he said, one might get policy information from several places and may need to combine, for instance, an organizational policy with a policy that applies to a particular resource.

A standard access control policy language such as XACML will not only eliminate the need for multiple, application-specific policy languages, but will also facilitate the development of tools for writing and managing XACML policies.

In a statement, San Jose, Calif.-based BEA Systems Inc., said it is working to incorporate support for XACML in future releases of its products. Lockhart said XACML 2.0 support will be provided in BEA's WebLogic Enterprise Security.

This news article originally appeared on the SearchWebServices site.

Tags: SAMLWS-policyOASIS SOA and Web services standardsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
SAML
UML-based SoaML attacks SOA services modeling issues
IBM, HP qualify on SAML 2.0
SOA governance, security concerns drive XACML interop
Microsoft, Liberty join for Web services identity interop
OASIS begins work on WS-Federation
Web 2.0 lacks the business impact of SOA, Burton warns
Eclipse and Novell join in Web service security effort
Liberty reaches out to open source
SAML declares victory, closes in on a billion IDs
WS-Security 1.1 approved
SAML Research

WS-policy
Data services mashup wizard latest for SOA
SOA triple play: Policy meets Semantic Web
WS02 releases wiki-style SOA registry
Post-Oracle: BEA gets back to SOA basics
W3C publishes WS-Policy as recommendation
SOA policy beyond Java and .NET
Mule extending Web services capabilities
Using ADO.NET and SDO for SOA data continuity
SOA standards WS-Policy, SCA and SDO advancing rapidly
Layer 7 releases custom policy SDK

OASIS SOA and Web services standards
BPEL4People and WS-HumanTask get reference implementation
BPEL4People seen uniting SOA/BPM
Mindreef updates SOA testing tools
The Content Assembly Mechanism and SOA data service layers
OASIS okays ebXML messaging standard
The standards behind Web services
SOA simplicity by committee?
Apache releases Java SCA
Why does SOA need BPEL?
JCP offers portlet spec

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



SOA Web Services: Application Server, Portals, Java, Microsoft .NET
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2001 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts