资源描述:
《基于wse3.0的web服务安全的应用研究》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、西南交通大学硕士学位论文基于WSE3.0的Web服务安全的应用研究姓名:付永军申请学位级别:硕士专业:计算机应用技术指导教师:唐慧佳20070501西南交通大学硕士研究生学位论文第
2、
3、页AbstractWebServicesprovidesakindofservicesorientedarchitecture·SOA,WhichisentirelybuiltuponthecurrentstandardsofIntemet.It’Sdistributed,100Secoupling,andindependentofplatfo
4、rms.WithWebServicesbeingusedwidely,itssecurityhasattractedmoreandmoleattention.Securityisacomplexproblem.Atthepresenttime,thespecificationsrelatedtosecurityofWebServicesmairdyhaveWS—Security,WS-poli锡XKMS,SAML,etc.ThoughthesespecificationsCallimplementsecurityofmess
5、ageinsomeways,theycallnotprovide锄integratedsecuritysolution.WebServicesrequiresasecuritysolutionforend-to-endapplication,includingencryption,digitalSignature.s洲ritymanagement,accesscontrolandSOon.First,thisthesisanalyzessecurityrequirementsofWebServices,andresearch
6、essecuntyofWebServices,includingsecuritytechnology,securityspecificationandthelatestdevelopment.Then,thisthesisanalyzesthepolicyframeworkandtheworkprocessofWebServicesEnhancements3.0,andilluminatestheapplicationofturnkeysecuritypolicyassertionandcllstompolicyassert
7、ionrespectively.Next,throughanalyzingsecuritymodelofWS—Securityspecificationanditsworkprinciple,aimingatsolvingthesecurityrequirementsofWebServices,akindofWebServicessecuritysolutionbasⅨlonpolicyarchitectureisdesigned.Thisthesisprovidesthewholeframework,describesth
8、eprocessofsecuritymessageexchange,andindicatestheadvantagesandthedisadvantagesofthesolution.Finally,aWebServicessomdtyapplicationsystemisdevelopedon.NETplatform1矾lhWSE3.0.Thisthesisintroducesthearchitectureofthesystemandtherealizationmethodsaimingatsecurityrequirem
9、ents,describestherealizationofthebasicsecurityfunctionmodules,andillustratestherealizationoftheadvancodsecurityfunctionmodules.Keywords:WebServicesSecurity;WS-security;WebServicesEnhancements3.o:Policy西南交通大学硕士研究生学位论文第1页第1章绪论1.1Web服务安全的研究背景Web服务技术基于许多不同软件应用程序的互操作性,而
10、这些应用程序通过Internet在各地各种系统中运行,通过使用XML、SOAP、UDDI、WSDL以及其他协议和机制,实现跨域且独立于平台的交互作用。正是由于Web服务这种分布式、异构的本质“1,使得Web服务的安全变得很复杂。而Web服务开发初始希望其简单易用,最初设计者选择了推迟定义解