Web Services Security Package - PowerPoint PPT Presentation

1 / 12
About This Presentation
Title:

Web Services Security Package

Description:

Web Services Security Package. By. Gilbert Ornelas. Kala Krishna Ramineni. Outline. Motivation ... Explore the combination of AOP with SAML as a solution. Introduction ... – PowerPoint PPT presentation

Number of Views:71
Avg rating:3.0/5.0
Slides: 13
Provided by: csU90
Category:

less

Transcript and Presenter's Notes

Title: Web Services Security Package


1
Web Services Security Package
  • By
  • Gilbert Ornelas
  • Kala Krishna Ramineni

2
Outline
  • Motivation
  • Introduction
  • Project Details
  • Future Work
  • Conclusions

3
Motivation
  • Explore the use of AOP in Web Services
  • security and maintenance
  • Need to develop tools to facilitate
  • Implementation of security in Web Services
  • Easy administration of Web Services
  • Single sign-on problem
  • Explore the combination of AOP with SAML as a
    solution

4
Introduction
  • Web Services is an emerging field
  • Increasingly adopted commercially
  • Security a major concern
  • Transfer of sensitive data
  • Proper authentication and authorization
  • Administration
  • Abundance of Web Services
  • Require easy administration
  • No proper tool

5
Terminology
  • Web Service
  • Loosely coupled software components delivered
    over Internet standard technologies.
  • SAML
  • Security Assertion Markup Language
  • Allows trust assertions to be specified using XML
  • XACML
  • eXtensible Access Control Markup Language
  • Defines rules to allow access to resources
  • Conditions for creating, combining, and
    processing rules to perform decisions.

6
The Project
  • AOP addresses many of the cross-cutting
    concerns in security and maintenance
  • Use AOP and XACML to provide authorization for
    Web Services that require it
  • Use AOP to complement SAML in providing single
    sign-on capabilities
  • Ability to hide selected Web Services from users

7
Layout
8
Deliverables
  • Created Web Service administration tool
  • Web Services can be made unavailable
  • Authentication and Authorization are provided
  • Created Web Service client
  • Displays available Web Services
  • Provides interface for the Web Services
  • Implemented tool that automatically creates the
    aspects to modify web services functionality

9
Admin Tool
10
Client
11
Future Work
  • Implementation of role-based security using AOP
  • Use AOP and SAML to provide single sign-on for
    Web Services
  • Add functionality to administrator tool
  • Logging using AOP
  • Add functionality to Web Service client
  • Ability to graphically use composite web services

12
Conclusions
  • Admin tool- for maintenance and security
    management through aspects
  • Code tangling across different Web Services is
    reduced
  • Security management made easier by the use of AOP
Write a Comment
User Comments (0)
About PowerShow.com