• Home
  • Search
  • Verifying policy-based web services security
  • Open Access IconOpen Access
  • Cite Icon19
  • https://doi.org/10.1145/1391956.1391957Copy DOI Icon

Verifying policy-based web services security

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

WS-SecurityPolicy is a declarative language for configuring web services security mechanisms. We describe a formal semantics for WS-SecurityPolicy and propose a more abstract language for specifying secure links between web services and their clients. We present the architecture and implementation of tools that (1) compile policy files from link specifications, and (2) verify by invoking a theorem prover whether a set of policy files run by any number of senders and receivers correctly implements the goals of a link specification, in spite of active attackers. Policy-driven web services implementations are prone to the usual subtle vulnerabilities associated with cryptographic protocols; our tools help prevent such vulnerabilities. We can verify policies when first compiled from link specifications, and also re-verify policies against their original goals after any modifications during deployment. Moreover, we present general security theorems for all configurations that rely on compiled policies.

Similar Papers
  • Supplementary Content
  • Citations68

Mastering Web Services Security

  • Jan 20, 2003
  • Zenodo (CERN European Organization for Nuclear Research)
  • Bret Hartman +2
  • Research Article
  • Citations86

Building web services for scientific grid applications

  • Mar 01, 2006
  • IBM Journal of Research and Development
  • G Kandaswamy +5
  • Book Chapter

Security of Web Servers and Web Services

  • Jan 01, 2010
  • Volker Hockmann +2
  • Research Article
  • Citations43

A Web Service Architecture for Enforcing Access Control Policies

  • Dec 27, 2005
  • Electronic Notes in Theoretical Computer Science
  • Claudio Agostino Ardagna +3
  • Conference Article
  • Citations10

API based security solutions for communication among web services

  • Dec 01, 2013
  • A Kanchana Rajaram +2
  • Research Article
  • Citations4

A Study on Web Service Analysis and Bio-information based Web Service Security Mechanism

  • Mar 31, 2014
  • International Journal of Security and Its Applications
  • Seong-Hoon Lee
  • Research Article
  • Citations1

Secure model for SOAP message communication in web services

  • Jan 01, 2016
  • International Journal of Advanced Intelligence Paradigms
  • S Chakaravarthi
  • Research Article
  • Citations6

MLSF: A Framework for Multi-Level Secure Composite Web Services

  • Dec 31, 2010
  • INTERNATIONAL JOURNAL ON Advances in Information Sciences and Service Sciences
  • J.G.R.Sathiaseelan - +2
  • Research Article
  • Citations2

Enhancement of Key Derivation in Web Service Security

  • Aug 18, 2017
  • Wireless Personal Communications
  • Abdelrahman Almahmoud +3
  • Research Article

Custom Security in Web Services

  • Aug 11, 2016
  • Indian Journal of Science and Technology
  • Balika J Chelliah +2
  • Conference Article
  • Citations19

Integrated Security Framework for Secure Web Services

  • Apr 01, 2010
  • Wenjun Zhang
  • Research Article
  • Citations150

A Trust-Based Context-Aware Access Control Model for Web-Services

  • Jul 01, 2005
  • Distributed and Parallel Databases
  • Rafae Bhatti +2
  • Research Article
  • Citations4

A Flexible and Secure Web Service Architectural Model Based on PKI and Agent Technology

  • Jun 01, 2010
  • International Journal for Infonomics
  • Maher Khemakhem +2
  • Research Article
  • Citations56

The importance of technology trust in Web services security

  • Dec 01, 2002
  • Information Management & Computer Security
  • Pauline Ratnasingam
  • Conference Article
  • Citations8

A Survey on Quantitative Evaluation of Web Service Security

  • Aug 01, 2016
  • Bo Zhou +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.