ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Web services security spec ready for deployment

Martin LaMonica CNET News.com

Published: 08 Apr 2004 10:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A much anticipated Web services specification has been approved as an industry standard, paving the way for broader usage of Web services protocols in mainstream business applications.

The Web Services Security, or WS-Security, technical committee within the Organisation for the Advancement of Structured Information Standards (OASIS) on Wednesday said several security-related technical specifications have been accepted by the group as standards. Now that the Web services security specifications are ratified, software and security companies can incorporate support for them into commercial products.

Web services protocols use XML to make it easier to share data between applications. The goal of the WS-Security specification is to improve interoperability between different security systems using these Extensible Markup Language-based protocols.

IBM and Microsoft originally authored a Web services security "road map" about two years ago. Then, in June 2002, the specification was submitted to OASIS for further development. Other security-related specifications aimed at better system interoperability are also under way at the World Wide Web Consortium and the Liberty Alliance.

Once business applications use WS-Security, Web applications should be able to share information regarding network access. For example, a system should be able to authenticate the identity of a person connecting to several networks at once or pass data between two applications securely.

The ability to share security information such as access privileges between applications will help promote Web services usage, particularly between trading partners that use the Internet to share corporate data, analysts said. Without reliable and interoperable security systems, businesses will be wary of fully moving their corporate applications to Web services standards, according to analysts.

WS-Security is expected to be used in a wide variety of products, including XML firewall products, Web services management software and network access security products.

One company involved in the development of WS-Security said ratification of the standard will help clarify which security standards have the most industry support from vendors.

"Many Web services security standards have emerged, creating confusion in the market. By relying on well-established and proven industry standards such as WS-Security and SAML (Security Assertion Markup Language), companies can securely expose Web services," Marc Chanliau, a product manager at Netegrity, said in a statement.

Another standards organisation, the Web Services Interoperability (WS-I) organisation, plans to publish guidelines on how to implement security standards to ensure interoperability later this year. WS-Security will be one of the standards that the WS-I will be incorporating into its security "profile," according to the WS-I.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
89 out of 222 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Broadband Consultant - IP DSLAM / ADSL - Immediate Start!

Broadband Testing - Thomson CPE DSL Modems & Routers - Internet Protocol Suite & Wireless Networking Protocols - TR-069 - Linux / Ubuntu Apply Now! ...

Senior Network Consultant - Urgent Requirement

Services, deployment of .Net apps over the public internet (security and bandwidth capacity sizing), platform authentication protocols and ...

TCP/IP Systems/software Test Engineer

My client is looking for the following experience: Skills/knowledge - Knowledge of software testing lifecycle - manual test design and execution ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains