Enterprise unified authentication and authorization system based on Web services

2011 ◽  
Vol 31 (2) ◽  
pp. 577-580
Author(s):  
He HU ◽  
Qin ZHANG ◽  
Guo-qing CHEN ◽  
Yang YANG
Author(s):  
Fábio Sarturi Prass

As  organizações  enfrentam  uma  série  de  problemas  para  atender  às  exigências  previstas  pelas  normas  e  modelos  de  segurança  de  software,  além  do  aumento contínuo das exigências relacionadas à segurança em sistemas. Uma série  de  normas  e  modelos  de  segurança  estão  disponíveis  na  literatura  a  fim  de  conduzirem  o  desenvolvimento  de  software  seguro.  Para  resolver  esse  problema  tem se os padrões que são amplamente utilizados em Engenharia de Software onde  eles  têm  sido  bem  sucedidas  na  melhoria  da  análise  e  projeto  por  encapsular  a  experiência  de  muitos  designers.  Padrões  de  segurança  são  um  desenvolvimento  recente, como forma de encapsular o conhecimento acumulado sobre o  design de  sistemas  de  segurança.  Apresenta se  aqui  dois  padrões  para  a  Web  Services:  Authentication and Authorization com utilização de Aspectos.


2008 ◽  
pp. 2356-2365
Author(s):  
Thomas Schmidt ◽  
Gerald Wippel ◽  
Klaus Glanzer ◽  
Karl Furst

Internet-focused application components of cooperating enterprises need comprehensive security technologies that go far beyond simple Internet authentication and authorization mechanisms. Basically, authentication is the process of determining the identity of a user or system, whereas authorization is the process of specifying who is allowed to access which resources. XML-based Web services is an upcoming and very promising technology. It enables the communication among Internet application components regardless of their implementation language. A major drawback of existing Web service approaches is the missing security conventions. Therefore, we concentrated all our effort on developing a holistic extended enterprise authentication and authorization system to facilitate agile and secure enterprise-spanning business processes with Web service-enabled application components.


2014 ◽  
Vol 1 (1) ◽  
pp. 9-34
Author(s):  
Bobby Suryajaya

SKK Migas plans to apply end-to-end security based on Web Services Security (WS-Security) for Sistem Operasi Terpadu (SOT). However, there are no prototype or simulation results that can support the plan that has already been communicated to many parties. This paper proposes an experiment that performs PRODML data transfer using WS-Security by altering the WSDL to include encryption and digital signature. The experiment utilizes SoapUI, and successfully loaded PRODML WSDL that had been altered with WSP-Policy based on X.509 to transfer a SOAP message.


2004 ◽  
Vol 124 (1) ◽  
pp. 176-181
Author(s):  
Tomoaki Maruo ◽  
Keinosuke Matsumoto ◽  
Naoki Mori ◽  
Masashi Kitayama ◽  
Yoshio Izumi

Sign in / Sign up

Export Citation Format

Share Document