摘要
针对Web服务的安全问题日益严重,本文结合实例分析面向服务架构的安全漏洞及安全需求,提出了构建端到端安全服务的解决方案,并在WS-Security、SAML等有关消息级安全的规范基础上,探讨了面向服务架构的安全架构设计与实现方法。通过采用Web服务和身份管理的最佳实践模型,保证了所传输消息的机密性、完整性、抗抵赖性,实现了安全的身份验证及单点登录。
An example is given to analyze its security flaws and security requirements in the services oriented architecture. Aimed at the increasingly severe security of SOA, a solution for building end to end security services is proposed, the specification concemed with Web services message-level security is put forward, such as WS-Security and SAML, according to these specifications, the design and realization method of services oriented security architecture are discussed. Through adopting the best practices model of Web services and identity management, it pledges the confidentiality, integrality and anti-denial of the transport message, implements the secure identity authentication and SSO( single sign-on).
出处
《计算机与现代化》
2009年第3期103-106,110,共5页
Computer and Modernization