Feeds

MS, IBM propose SOAP security kit for Web services

Flexible, extensible, maybe even sensible?

  • alert
  • submit to reddit

Build a business case: developing custom apps

A team of researchers from Microsoft, IBM and VeriSign have put together a preliminary proposal for securing Web services with SOAP (Simple Object Access Protocol) extensions which will work with a variety of authentication and encryption schemes.

Called WS-Security (Web Services Security Language), the proposed specification is said to be a general-purpose kit for developing security mechanisms tailored to individual needs. (The authors clearly realize that such a kit does not in itself guarantee security, since it may be implemented well or poorly.)

The document provides a fairly solid list of problems along with examples of how they might be addressed with WSS. Some are better than others, and the team is soliciting criticism and suggestions from outside, though there doesn't appear to be a convenient link in the document to a contact person for the project.

The document shows considerable awareness of the technical pitfalls, and makes a decent argument that something along these lines is better than nothing. The goal, obviously, is to make Internet communications confidential, tamper-proof, and reliably authenticated. Insofar as that can be accomplished without making it a compulsory regime, or a de facto compulsory regime by virtue of the colossal marketing and communications might of the three companies involved, we're all in favor of it.

"WS-Security...is designed to be used as the basis for the construction of a wide variety of security models including PKI, Kerberos, and SSL. Specifically, WS-Security provides support for multiple security tokens, multiple trust domains, multiple signature formats, and multiple encryption technologies," the authors say.

That's a claim which needs to be examined closely. It's not difficult to imagine how a trio like this could promote each other's interests to the detriment of competitors with a scheme like WSS. On the other hand, if it really turns out as flexible as is claimed, then I can't really fault it unless it ultimately fails to live up to its technical goals.

One is naturally, and rightly, wary when heavyweight corporations join forces to issue a specification which could affect millions of users. But so long as WSS remains a contribution and not a mandate, and so long as it doesn't inhibit research into alternative approaches, and so long as it doesn't become chiefly a platform for triangular business promotion, there can be no harm in having another set of tools to choose from. It might even develop into something quite good -- you never know. ®

5 things you didn’t know about cloud backup

More from The Register

next story
PEAK LANDFILL: Why tablet gloom is good news for Windows users
Sinofsky's hybrid strategy looks dafter than ever
Leaked Windows Phone 8.1 Update specs tease details of Nokia's next mobes
New screen sizes, dual SIMs, voice over LTE, and more
Fiendishly complex password app extension ships for iOS 8
Just slip it in, won't hurt a bit, 1Password makers urge devs
Mozilla keeps its Beard, hopes anti-gay marriage troubles are now over
Plenty on new CEO's todo list – starting with Firefox's slipping grasp
Apple: We'll unleash OS X Yosemite beta on the MASSES on 24 July
Starting today, regular fanbois will be guinea pigs, it tells Reg
Another day, another Firefox: Version 31 is upon us ALREADY
Web devs, Mozilla really wants you to like this one
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
Cloudy CoreOS Linux distro declares itself production-ready
Lightweight, container-happy Linux gets first Stable release
prev story

Whitepapers

7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?