Home > SOA News > New security standards seek to establish trust
SOA News:
EMAIL THIS

New security standards seek to establish trust

By Colleen Frye, News Writer
04 Aug 2005 | SearchWebServices.com

News on SOA, EAI, Web services
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Industry cooperation around security in a Web services world has taken several steps forward recently with the announcement that three more specifications in the IBM/Microsoft Web Services (WS-*) Security Roadmap are being submitted to OASIS in September, and a successful interoperability demo involving multiple federated identity protocols. Both took place at the Burton Group's Catalyst Conference last month.

WS-Trust, WS-SecurityPolicy and WS-SecureConversation build on WS-Security, which was ratified by OASIS in 2004. WS-Trust and WS-SecureConversation were co-authored with vendors such as Actional Corp., BEA Systems Inc., Computer Associates International Inc., Oracle Corp., RSA Security Inc., VeriSign Inc. and others. WS-SecurityPolicy was co-authored with RSA Security and VeriSign.

The announcement...is yet another indication of the industry rallying around interoperability through SOAP-based Web services.
Ari Bixhorn
Director of Web Services Strategy, Microsoft

"While WS-Security defines the basic mechanisms for providing secure messaging, WS-Trust defines extensions to WS-Security that provide ways to establish and broker trust relationships between organizations," said Ari Bixhorn, director of Web services strategy at Microsoft. "It does this by providing a mechanism to move between various security tokens types, including Kerberos, X.509, and SAML [Security Assertion Markup Language]. Typically this is done through the use of a Security Token Service [STS], which is a Web service that issues security tokens that can be trusted by both the sender and receiver of a Web services message."

In a Web services environment, "new supply chains are built to work across multiple systems; this ecosystem can communicate and collaborate securely using open standards," said Venkat Raghavan, program director of Security, Policy and Compliance for IBM Tivoli. "The challenge is, how do we have a common notion of identity and security that works across multiple platforms, technologies, middleware -- across the value chain. WS-Trust gives you a way to homogenize disparate systems."

Organizations already have different technologies in place for authenticating users, Raghavan said. "The goal is not to replace but to leverage existing security technologies to allow business process integration."

Gerry Gebel, a senior analyst at the Burton Group in Midvale, Utah, said WS-Trust is significant, particularly for hybrid environments. "You can give one style of token and request another in return."

The second spec, WS-SecurityPolicy, defines general security policy assertions that apply to Web services security. For example, WS-SecurityPolicy would be used to implement the Web Services Interoperability Basic Security Profile (WS-I BSP), according to Anthony Nadalin, distinguished engineer and chief security architect of the IBM Software Group. "Other [examples] include being able to describe the security capabilities and contraints of a Web service."

Meanwhile, WS-SecureConversation "defines extensions to allow security context establishment and sharing, and session key derivation," Nadalin said. "This allows contexts to be established and potentially more efficient keys or new key material to be exchanged, thereby increasing the overall performance and security of the subsequent exchanges."

WS-Trust and WS-Federation, another piece of the WS-* road map, were part of the interoperability demonstration at the conference. The demo featured three scenarios around an automotive supply chain: multiprotocol hubs, multiprotocol translator hubs and protocol translation using WS-Trust STS. Identities were securely managed and exchanged via SAML 1.0, SAML 2.0, Liberty Alliance WS-Federation and WS-Trust protocols.

"Previous demos focused on a single protocol and a single version of a protocol," Gebel said. "This is a sign of maturity for federation protocols."

For more information

Learn why standards and tools are vital to Web services security

 

See how one vendor is facilitating greater control of Web services security policy

The demo showed that "if you're on the auto dealer side and bought a Hewlett-Packard [identity management] product, for example, and another manufacturer bought a different product, they all can make the handshake," said Rebecca Xiong, product marketing manager at DataPower Technology Inc., Cambridge, Mass., one of 14 vendors that participated in the demo. "The more [vendors] supporting protocols, the easier it is for consumers to build out their Web sites and work with partners."

Once OASIS gets the WS-Trust, WS-SecurityPolicy, and WS-SecureConversation specifications, a technical committee will be formed and the standardization process will begin, Nadalin said. As for the remaining specs in the road map -- WS-Federation, WS-Privacy and WS-Authorization -- "IBM has committed to take all the specifications in the WS Security Roadmap to a standards body. I can't comment on when and where these specifications will be taken," Nadalin said. While WS-Federation has already been involved in several interoperability demos, WS-Privacy and WS-Authorization "still remain unpublished at this time."

Microsoft's Bixhorn points to the progress made so far. "The announcement around WS-Trust, WS-SecurityPolicy and WS-SecureConversation is yet another indication of the industry rallying around interoperability through SOAP-based Web services," he said.



Tags: SAMLWS-SXVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Web services transaction specifications
Express Logic ThreadX teamed with server to support Web services
SOA specs for energy industry planned
OASIS okays ebXML messaging standard
OASIS approves WS-Transaction 1.1
OASIS begins work on WS-Federation
WS-Policy on SOA fast track, W3C approval this summer
Web services work on insurance claims
webMethods integrates Infravio's SOA street cred
SOA and BPM tools seen outpacing customer expectations
Gavin King on advanced state management

SAML
UML-based SoaML attacks SOA services modeling issues
IBM, HP qualify on SAML 2.0
SOA governance, security concerns drive XACML interop
Microsoft, Liberty join for Web services identity interop
OASIS begins work on WS-Federation
Web 2.0 lacks the business impact of SOA, Burton warns
Eclipse and Novell join in Web service security effort
Liberty reaches out to open source
SAML declares victory, closes in on a billion IDs
WS-Security 1.1 approved
SAML Research

SOA and Web services standards
In search of enterprise mashup standards
IBM and Sun reportedly in merger talks
SOA specs for energy industry planned
Web publishing spec released
OASIS okays ebXML messaging standard
Web services extend server spec
OpenAjaxHub spec emerges
The hunt for XML interoperability
Apache releases Java SCA
W3C publishes WS-Policy as recommendation

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
WS-Transaction  (SearchSOA.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



SOA Web Services: Application Server, Portals, Java, Microsoft .NET
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2001 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts