资源描述:
《(最新)基于wse3.0的web服务安全的应用研究》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、西南交通大学硕士学位论文基于WSE3.0的Web服务安全的应用研究姓名:付永军申请学位级别:硕士专业:计算机应用技术指导教师:唐慧佳20070501西南交通大学硕士研究生学位论文第
2、
3、页AbstractWebServicesprovidesakindofservicesorientedarchitecture·SOA,WhichisentirelybuiltuponthecurrentstandardsofIntemet.It’Sdistributed,100Secoupling,andindependentofplatf
4、orms.WithWebServicesbeingusedwidely,itssecurityhasattractedmoreandmoleattention.Securityisacomplexproblem.Atthepresenttime,thespecificationsrelatedtosecurityofWebServicesmairdyhaveWS—Security,WS-poli锡XKMS,SAML,etc.ThoughthesespecificationsCallimplementsecurityofme
5、ssageinsomeways,theycallnotprovide锄integratedsecuritysolution.WebServicesrequiresasecuritysolutionforend-to-endapplication,includingencryption,digitalSignature.s洲ritymanagement,accesscontrolandSOon.First,thisthesisanalyzessecurityrequirementsofWebServices,andresea
6、rchessecuntyofWebServices,includingsecuritytechnology,securityspecificationandthelatestdevelopment.Then,thisthesisanalyzesthepolicyframeworkandtheworkprocessofWebServicesEnhancements3.0,andilluminatestheapplicationofturnkeysecuritypolicyassertionandcllstompolicyas
7、sertionrespectively.Next,throughanalyzingsecuritymodelofWS—Securityspecificationanditsworkprinciple,aimingatsolvingthesecurityrequirementsofWebServices,akindofWebServicessecuritysolutionbasⅨlonpolicyarchitectureisdesigned.Thisthesisprovidesthewholeframework,descri
8、bestheprocessofsecuritymessageexchange,andindicatestheadvantagesandthedisadvantagesofthesolution.Finally,aWebServicessomdtyapplicationsystemisdevelopedon.NETplatform1矾lhWSE3.0.Thisthesisintroducesthearchitectureofthesystemandtherealizationmethodsaimingatsecurityre
9、quirements,describestherealizationofthebasicsecurityfunctionmodules,andillustratestherealizationoftheadvancodsecurityfunctionmodules.Keywords:WebServicesSecurity;WS-security;WebServicesEnhancements3.o:Policy西南交通大学硕士研究生学位论文第1页第1章绪论1.1Web服务安全的研究背景Web服务技术基于许多不同软件应用程序
10、的互操作性,而这些应用程序通过Internet在各地各种系统中运行,通过使用XML、SOAP、UDDI、WSDL以及其他协议和机制,实现跨域且独立于平台的交互作用。正是由于Web服务这种分布式、异构的本质“1,使得Web服务的安全变得很复杂。而Web服务开发初始希望其简单易用,最初设计者选择了推迟定义解