Abstract
The goal of service oriented architectures (SOA) is to allow a message based and loosely coupled interaction between different web services. This approach allows the orchestration of web services in distributed, heterogeneous applications where the different services can be implemented in different programming languages, run on different machines and be based on different protocols. The adoption of web services to integrate systems within an organization and with partners is strongly dependent on the security standards that accompany service oriented architectures (SOA). The XML (Extensible Markup Language) Signature standard plays a key role here. For protecting such a distributed application, XML Signatures are used on several levels and for different challenges, for example to guarantee the integrity and authenticity of the exchanged messages and their authentication information, as well as the audit trails and to provide non-repudiation. The paper describes the role of XML Signatures for protecting Enterprise Service Bus (ESB) based SOA applications.
Chapter PDF
Similar content being viewed by others
References
Kollmorgen, R., Kessler, D., Hermann, E., Jung, F.: Digital signatures in XML, http://asia.cnet.com/builder/architect/system/0,39009336,39100045,00.htm
XML Signature Syntax and Processing, http://www.w3.org/TR/xmldsig-core/
Kuznetsov, E.: XML Web services security best practices, http://www.builderau.com.au/manage/work/0,39024674,39130825,00.htm
Liberty ID_FF Architecture Overview, Version: 1.2-errata-v1.0, http://www.projectliberty.org/specs/draft-liberty-idff-arch-overview-1.2-errata-v1.0.pdf
Software AG ESI Security and SOA Security white papers, http://www.softwareag.com
SOAP Version 1.2 Part 0, http://www.w3.org/TR/2003/REC-soap12-part0-20030624/
OASIS Web Service Security: SOAP Message Security, http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0.pdf
Long-term Archive And Notary Services (LTANS) Internet-Draft, http://ietfreport.isoc.org/ids/draft-ietf-ltans-ers-02.txt
SAML v2.0, OASIS, http://www.oasis-open.org/specs/index.php#samlv2.0
IETF Working Group on Transport Layer Security, http://www1.treese.org/ietf-tls/
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2005 IFIP International Federation for Information Processing
About this paper
Cite this paper
Hermann, E., Kessler, D. (2005). XML Signatures in an Enterprise Service Bus Environment. In: Dittmann, J., Katzenbeisser, S., Uhl, A. (eds) Communications and Multimedia Security. CMS 2005. Lecture Notes in Computer Science, vol 3677. Springer, Berlin, Heidelberg. https://doi.org/10.1007/11552055_44
Download citation
DOI: https://doi.org/10.1007/11552055_44
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-540-28791-9
Online ISBN: 978-3-540-31978-8
eBook Packages: Computer ScienceComputer Science (R0)