2005Unpublished venueRequires access

Core Security Patterns: Best Practices and Strategies for J2EE, Web Services, and Identity Management

Christopher Steel, Ramesh Nagappan, Ray Lai

Open publisher page 205 citations

Abstract

Foreword by Judy Lin. Foreword by Joe Uniejewski. Preface. Acknowledgments. About the Authors. I. INTRODUCTION. 1. Security by Default. Challenges Around Security What Are the Weakest Links? The Impact of Application Security The Four W's Strategies for Building Robust Security Proactive and Reactive Security The Importance of Security Compliance The Importance of Identity Management The Importance of Java Technology Making Security a Business Enabler Summary References 2. Basics of Security. Security Requirements and Goals The Role of Cryptography in Security The Role of Secure Sockets Layer (SSL) The Importance and Role of LDAP in Security Common Challenges in Cryptography Threat Modeling Identity Management Summary References II. JAVA SECURITY ARCHITECTURE AND TECHNOLOGIES. 3. The Java 2 Platform Security. Java Security Architecture Java Applet Security Java Web Start Security Java Security Management Tools J2ME Security Architecture Java Card Security Architecture Securing the Java Code Summary References 4. Java Extensible Security Architecture and APIs. Java Extensible Security Architecture Java Cryptography Architecture (JCA) Java Cryptographic Extensions (JCE) Java Certification Path API (CertPath) Java Secure Socket Extension (JSSE) Java Authentication and Authorization Service (JAAS) Java Generic Secure Services API (JGSS) Simple Authentication and Security Layer (SASL) Summary References 5. J2EE Security Architecture. J2EE Architecture and Its Logical Tiers J2EE Security Definitions J2EE Security Infrastructure J2EE Container-Based Security J2EE Component/Tier-Level Security J2EE Client Security EJB Tier or Component Security EIS Integration Tier-Overview J2EE Architecture--Network Topology J2EE Web Services Security-Overview Summary References III. WEB SERVICES SECURITY AND IDENTITY MANAGEMENT. 6. Web Services Security--Standards and Technologies. Web Services Architecture and Its Building Blocks Web Services Security--Core Issues Web Services Security Requirements Web Services Security Standards XML Signature XML Encryption XML Key Management System (XKMS) OASIS Web Services Security (WS-Security) WS-I Basic Security Profile Java-Based Web Services Security Providers XML-Aware Security Appliances Summary References 7. Identity Management Standards and Technologies. Identity Management--Core Issues Understanding Network Identity and Federated Identity Introduction to SAML SAML Architecture SAML Usage Scenarios The Role of SAML in J2EE-Based Applications and Web Services Introduction to Liberty Alliance and Their Objectives Liberty Alliance Architecture Liberty Usage Scenarios The Nirvana of Access Control and Policy Management Introduction to XACML XACML Data Flow and Architecture XACML Usage Scenarios Summary References IV. SECURITY DESIGN METHODOLOGY, PATTERNS, AND REALITY CHECKS. 8. The Alchemy of Security Design--Methodology, Patterns, and Reality Checks. The Rationale Secure UP Security Patterns Security Patterns for J2EE, Web Services, Identity Management, and Service Provisioning Reality Checks Security Testing Adopting a Security Framework Refactoring Security Design Service Continuity and Recovery Conclusion References V. DESIGN STRATEGIES AND BEST PRACTICES. 9. Securing the Web Tier--Design Strategies and Best Practices. Web-Tier Security Patterns Best Practices and Pitfalls References 10. Securing the Tier--Design Strategies and Best Practices. Security Considerations in the Tier Tier Security Patterns Best Practices and Pitfalls References 11. Securing Web Services--Design Strategies and Best Practices. Web Services Security Protocols Stack Web Services Security Infrastructure Web Services Security Patterns Best Practices and Pitfalls Best Practices References 12. Securing the Identity--Design Strategies and Best Practices. Identity Management Security Patterns Best Practices and Pitfalls References 13. Secure Service Provisioning--Design Strategies and Best Practices. Challenges User Account Provisioning Architecture Introduction to SPML Service Provisioning Security Pattern Best Practices and Pitfalls Summary References VI. PUTTING IT ALL TOGETHER. 14. Building End-to-End Security Architecture--A Case Study. Overview Use Case Scenarios Application Architecture Security Architecture Design Development Testing Deployment Summary Lessons Learned Pitfalls Conclusion References VII. PERSONAL IDENTIFICATION USING SMART CARDS AND BIOMETRICS. 15. Secure Personal Identification Strategies Using Smart Cards and Biometrics. Physical and Logical Access Control Enabling Technologies Smart Card-Based Identification and Authentication Biometric Identification and Authentication Multi-factor Authentication Using Smart Cards and Biometrics Best Practices and Pitfalls References Index.

About this research paper

What this paper is about

Foreword by Judy Lin. Foreword by Joe Uniejewski. Preface. Acknowledgments. About the Authors. I. INTRODUCTION. 1. Security by Default. Challenges Around Security What Are the Weakest Links? The Impact of Application Security The Four W's Strategies for Building Robust Security Proactive and Reactive Security The Importance of Security Compliance The Importance of Identity Management The Importance of Java Technology Making Security a Business Enabler Summary References 2. Basics of Security. Security Requirements and Goals The Role of Cryptography in Security The Role of Secure Sockets Layer (SSL) The Importance and Role of LDAP in Security Common Challenges in Cryptography Threat Modeling Identity Management Summary References II. JAVA SECURITY ARCHITECTURE AND TECHNOLOGIES. 3. The Java 2 Platform Security. Java Security Architecture Java Applet Security Java Web Start Security Java Security Management Tools J2ME Security Architecture Java Card Security Architecture Securing the Java Code Summary References 4. Java Extensible Security Architecture and APIs. Java Extensible Security Architecture Java Cryptography Architecture (JCA) Java Cryptographic Extensions (JCE) Java Certification Path API (CertPath) Java Secure Socket Extension (JSSE) Java Authentication and Authorization Service (JAAS) Java Generic Secure Services API (JGSS) Simple Authentication and Security Layer (SASL) Summary References 5. J2EE Security Architecture. J2EE Architecture and Its Logical Tiers J2EE Security Definitions J2EE Security Infrastructure J2EE Container-Based Security J2EE Component/Tier-Level Security J2EE Client Security EJB Tier or Component Security EIS Integration Tier-Overview J2EE Architecture--Network Topology J2EE Web Services Security-Overview Summary References III. WEB SERVICES SECURITY AND IDENTITY MANAGEMENT. 6. Web Services Security--Standards and Technologies. Web Services Architecture and Its Building Blocks Web Services Security--Core Issues Web Services Security Requirements Web Services Security Standards XML Signature XML Encryption XML Key Management System (XKMS) OASIS Web Services Security (WS-Security) WS-I Basic Security Profile Java-Based Web Services Security Providers XML-Aware Security Appliances Summary References 7. Identity Management Standards and Technologies. Identity Management--Core Issues Understanding Network Identity and Federated Identity Introduction to SAML SAML Architecture SAML Usage Scenarios The Role of SAML in J2EE-Based Applications and Web Services Introduction to Liberty Alliance and Their Objectives Liberty Alliance Architecture Liberty Usage Scenarios The Nirvana of Access Control and Policy Management Introduction to XACML XACML Data Flow and Architecture XACML Usage Scenarios Summary References IV. SECURITY DESIGN METHODOLOGY, PATTERNS, AND REALITY CHECKS. 8. The Alchemy of Security Design--Methodology, Patterns, and Reality Checks. The Rationale Secure UP Security Patterns Security Patterns for J2EE, Web Services, Identity Management, and Service Provisioning Reality Checks Security Testing Adopting a Security Framework Refactoring Security Design Service Continuity and Recovery Conclusion References V. DESIGN STRATEGIES AND BEST PRACTICES. 9. Securing the Web Tier--Design Strategies and Best Practices. Web-Tier Security Patterns Best Practices and Pitfalls References 10. Securing the Tier--Design Strategies and Best Practices. Security Considerations in the Tier Tier Security Patterns Best Practices and Pitfalls References 11. Securing Web Services--Design Strategies and Best Practices. Web Services Security Protocols Stack Web Services Security Infrastructure Web Services Security Patterns Best Practices and Pitfalls Best Practices References 12. Securing the Identity--Design Strategies and Best Practices. Identity Management Security Patterns Best Practices and Pitfalls References 13. Secure Service Provisioning--Design Strategies and Best Practices. Challenges User Account Provisioning Architecture Introduction to SPML Service Provisioning Security Pattern Best Practices and Pitfalls Summary References VI. PUTTING IT ALL TOGETHER. 14. Building End-to-End Security Architecture--A Case Study. Overview Use Case Scenarios Application Architecture Security Architecture Design Development Testing Deployment Summary Lessons Learned Pitfalls Conclusion References VII. PERSONAL IDENTIFICATION USING SMART CARDS AND BIOMETRICS. 15. Secure Personal Identification Strategies Using Smart Cards and Biometrics. Physical and Logical Access Control Enabling Technologies Smart Card-Based Identification and Authentication Biometric Identification and Authentication Multi-factor Authentication Using Smart Cards and Biometrics Best Practices and Pitfalls References Index.

Why it matters

OpenAlex reports 205 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Foreword by Judy Lin. Foreword by Joe Uniejewski. Preface. Acknowledgments. About the Authors. I. INTRODUCTION. 1. Security by Default. Challenges Around Security What Are the Weakest Links? The Impact of Application Security The Four W's Strategies for Building Robust Security Proactive and Reactive Security The Importance of Security Compliance The Importance of Identity Management The Importance of Java Technology Making Security a Business Enabler Summary References 2. Basics of Security. Security Requirements and Goals The Role of Cryptography in Security The Role of Secure Sockets Layer (SSL) The Importance and Role of LDAP in Security Common Challenges in Cryptography Threat Modeling Identity Management Summary References II. JAVA SECURITY ARCHITECTURE AND TECHNOLOGIES. 3. The Java 2 Platform Security. Java Security Architecture Java Applet Security Java Web Start Security Java Security Management Tools J2ME Security Architecture Java Card Security Architecture Securing the Java Code Summary References 4. Java Extensible Security Architecture and APIs. Java Extensible Security Architecture Java Cryptography Architecture (JCA) Java Cryptographic Extensions (JCE) Java Certification Path API (CertPath) Java Secure Socket Extension (JSSE) Java Authentication and Authorization Service (JAAS) Java Generic Secure Services API (JGSS) Simple Authentication and Security Layer (SASL) Summary References 5. J2EE Security Architecture. J2EE Architecture and Its Logical Tiers J2EE Security Definitions J2EE Security Infrastructure J2EE Container-Based Security J2EE Component/Tier-Level Security J2EE Client Security EJB Tier or Component Security EIS Integration Tier-Overview J2EE Architecture--Network Topology J2EE Web Services Security-Overview Summary References III. WEB SERVICES SECURITY AND IDENTITY MANAGEMENT. 6. Web Services Security--Standards and Technologies. Web Services Architecture and Its Building Blocks Web Services Security--Core Issues Web Services Security Requirements Web Services Security Standards XML Signature XML Encryption XML Key Management System (XKMS) OASIS Web Services Security (WS-Security) WS-I Basic Security Profile Java-Based Web Services Security Providers XML-Aware Security Appliances Summary References 7. Identity Management Standards and Technologies. Identity Management--Core Issues Understanding Network Identity and Federated Identity Introduction to SAML SAML Architecture SAML Usage Scenarios The Role of SAML in J2EE-Based Applications and Web Services Introduction to Liberty Alliance and Their Objectives Liberty Alliance Architecture Liberty Usage Scenarios The Nirvana of Access Control and Policy Management Introduction to XACML XACML Data Flow and Architecture XACML Usage Scenarios Summary References IV. SECURITY DESIGN METHODOLOGY, PATTERNS, AND REALITY CHECKS. 8. The Alchemy of Security Design--Methodology, Patterns, and Reality Checks. The Rationale Secure UP Security Patterns Security Patterns for J2EE, Web Services, Identity Management, and Service Provisioning Reality Checks Security Testing Adopting a Security Framework Refactoring Security Design Service Continuity and Recovery Conclusion References V. DESIGN STRATEGIES AND BEST PRACTICES. 9. Securing the Web Tier--Design Strategies and Best Practices. Web-Tier Security Patterns Best Practices and Pitfalls References 10. Securing the Tier--Design Strategies and Best Practices. Security Considerations in the Tier Tier Security Patterns Best Practices and Pitfalls References 11. Securing Web Services--Design Strategies and Best Practices. Web Services Security Protocols Stack Web Services Security Infrastructure Web Services Security Patterns Best Practices and Pitfalls Best Practices References 12. Securing the Identity--Design Strategies and Best Practices. Identity Management Security Patterns Best Practices and Pitfalls References 13. Secure Service Provisioning--Design Strategies and Best Practices. Challenges User Account Provisioning Architecture Introduction to SPML Service Provisioning Security Pattern Best Practices and Pitfalls Summary References VI. PUTTING IT ALL TOGETHER. 14. Building End-to-End Security Architecture--A Case Study. Overview Use Case Scenarios Application Architecture Security Architecture Design Development Testing Deployment Summary Lessons Learned Pitfalls Conclusion References VII. PERSONAL IDENTIFICATION USING SMART CARDS AND BIOMETRICS. 15. Secure Personal Identification Strategies Using Smart Cards and Biometrics. Physical and Logical Access Control Enabling Technologies Smart Card-Based Identification and Authentication Biometric Identification and Authentication Multi-factor Authentication Using Smart Cards and Biometrics Best Practices and Pitfalls References Index.

Key concepts: Computer science, Security service, Computer security model, Computer security, Security information and event management, Sherwood Applied Business Security Architecture, Cloud computing security, Web application security

Related papers

Back to paper searchBrowse research topicsOriginal source
Core Security Patterns: Best Practices and Strategies for J2EE, Web Services, and Identity Management — Research Paper | ScholarLens