计算机科学 ›› 2010, Vol. 37 ›› Issue (8): 32-39.

• 综述 • 上一篇    下一篇

Web服务安全问题研究

贺正求,吴礼发,洪征,王睿,李华波   

  1. (解放军理工大学指挥自动化学院 南京210007)
  • 出版日期:2018-12-01 发布日期:2018-12-01
  • 基金资助:
    本文受国防预研基金(51406020105JB8103)资助。

Research on Security Problems of Web Service

HE Zheng-qiu,WU Li-fa,HONG Zheng,WANG Rui,LI Hua-bo   

  • Online:2018-12-01 Published:2018-12-01

摘要: Web服务具有平台无关性、动态性、开放性和松散藕合等特征,这给基于异构平台的应用集成带来极大便利,同时也使其自身面临许多独特的安全问题。Web服务的安全性对其发展前景产生重要的影响,也是目前Web服务并没有进入大规模应用阶段的主要原因之一。总结了Web服务存在的主要安全问题;概述了已有的Web服务安全标准;然后从消息层安全、Web服务安全策略、Web服务组合安全、身份与信任管理、Web服务访问控制、Web服务攻击与防御、安全Web服务开发等方面详细分析了目前有代表性的Web服务关键安全技术解决方案;结合已有的研究成果,讨论了Web服务安全未来的研究动向及面临的挑战。

关键词: Web服务,安全,策略,服务组合,信任,访问控制,攻击

Abstract: Web service is characterized by its platform-independence, dynamic, openness, and loose coupling. These chary cteristics greatly facilitate the application-to-application integration based on heterogeneous platform, but they also lead to many security problems. The security of Web service deeply influences its development and is also one of the main reasons why Web service has not been adopted widely. In this paper, we firstly summarized the main security problems of Web service and outlined the existing security specifications for Web service, and then we analyzed the representative solutions to Web service security in detail, including message security, security policy, security in Web service composition,identity and trust management, access control, attacks and defenses, as well as development of secure Web services. On the basis of current research achievemented, this paper also presented a discussion on the future research directions and the challenges of Web service security.

Key words: Web service, Security, Policy, Service composition, Trust, Access control, Attacks

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!