Web Services Secure Conversation Language (WS-SecureConversation)
Steven W. Anderson, OpenNetwork Jeff Bohren
Abstract
Steven W. Anderson, OpenNetwork Jeff Bohren
Abstract
This specification defines extensions that build on [WS-Security] and [WS-Trust] to provide secure communication across one or more messages. Specifically, this specification defines mechanisms for establishing and sharing security contexts, and deriving keys from established security contexts (or any shared secret). Modular Architecture By using the XML, SOAP, and WSDL extensibility models, the WS-* specifications are designed to be composed with each other to provide a rich Web services environment. WS-SecureConversation by itself does not provide a complete security solution for Web services. WS-SecureConversation is a building block that is used in conjunction with other Web service and application-specific protocols to accommodate a wide variety of security models. Status This WS-SecureConversation Specification is a revised public draft release and is provided for review and evaluation only. Actional, BEA, Computer Associates, IBM, Layer7, Microsoft, Oblix, OpenNetwork, Ping Identity, Reactivity, RSA Security, and VeriSign hope to solicit your contributions and suggestions in the near future. Actional, BEA, Computer Associates, IBM, Layer7, Microsoft, Oblix, OpenNetwork, Ping Identity,
OpenAlex reports 53 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
This specification defines extensions that build on [WS-Security] and [WS-Trust] to provide secure communication across one or more messages. Specifically, this specification defines mechanisms for establishing and sharing security contexts, and deriving keys from established security contexts (or any shared secret). Modular Architecture By using the XML, SOAP, and WSDL extensibility models, the WS-* specifications are designed to be composed with each other to provide a rich Web services environment. WS-SecureConversation by itself does not provide a complete security solution for Web services. WS-SecureConversation is a building block that is used in conjunction with other Web service and application-specific protocols to accommodate a wide variety of security models. Status This WS-SecureConversation Specification is a revised public draft release and is provided for review and evaluation only. Actional, BEA, Computer Associates, IBM, Layer7, Microsoft, Oblix, OpenNetwork, Ping Identity, Reactivity, RSA Security, and VeriSign hope to solicit your contributions and suggestions in the near future. Actional, BEA, Computer Associates, IBM, Layer7, Microsoft, Oblix, OpenNetwork, Ping Identity,
Key concepts: Computer science, Web service, SOAP, World Wide Web, Web application security, IBM, Computer security, XML