Secure Password-Based Authenticated Key Exchange
for Web Services
Summary:
Grid Computing and Web Services
The term “Grid” refers to systems and applications that integrate and manage resources and services distributed across multiple control domains [GRID]. Pioneered in an e-science context, Grid technologies are also
generating interest in industry, as a result of their apparent relevance to commercial distributed-computing applications [PHYS]. The results of this research have been incorporated into a widely used software system
called the Globus Toolkit ® (GT) [GT, GTO] that uses public key technologies to address issues of single sign-on, delegation, and identity. The Grid Security Infrastructure (GSI) is the name given to the portion of the
Globus Toolkit that implements security functionality. The recent definition of the Web Service Resource Framework (WSRF) specification and other elements of the Open Grid Services Architecture (OGSA) within OASIS and the Global Grid Forum (GGF) introduce new challenges and opportunities for Grid security [WSRF, OGSA, GGF]. In particular, integration with Web
services and hosting environment technologies introduces opportunities to leverage emerging security technologies such as described in the WS-Security, WS-Trust and WS-SecureConversation specifications [WSSec, WSTr, WSSC] Web Services Security Web Services Security is still immature in many ways, which is evident by the number of emerging
specifications that are competing and in flux. Recently, however, the basic underpinnings for SOAP message security have been defined by the standardized WS-Security specifications in OASIS [WSSec].
WS-Trust and WS-SecureConversation are proposed extensions of the WS-Security specification, defining message primitives and interfaces for security context establishment, sharing, and session key derivation [WSTr,
WSSC]. Although these specifications have not yet been standardized, the associated authors have publicly stated their intension to do so.
Format:![]()
Pages : 19
Size: 450 kb
Author: Liang Fang,Samuel Meder, Olivier Chevassut, and Frank Siebenlist
Download:
Secure Password-Based Authenticated Key Exchange
for Web Services
