member login

WebServices dot org

Todays Featured Content:

StrikeIron Jump-Starts 2008 with Multiple Industry Honors

CMP’s Intelligent Enterprise Web site announced its 2008 Editors’ Choice Award winners with StrikeIron included among its 36 “Companies to Watch” in the enterprise application category. StrikeIron was also included in Robin Bloor’s list of “10 IT Companies to Watch in 2008.”

StrikeIron Expands Web Services Marketplace with New Financial and Business Data Services from Gale

In-depth financial and corporate information on hundreds of thousands of U.S. and international companies: Two new Financial and Business data services from Gale, part of Cengage Learning, have been added to StrikeIron's expanding Web Services Marketplace: Gale Business Information Web Service 1.0.0 and Gale Business Intelligence Web Service 1.0.0.

StrikeIron Delivers Data Web Services via IBM QEDWiki

StrikeIron Inc., a provider of Data as a Service (DaaS), today announced that it has aligned with IBM to deliver premium web services via IBM's enterprise mashup maker QEDWiki. Content available includes business intelligence services such as multiple D&B services, Address Verification, Email Verification, Currency Rates and many more.

StrikeIron Super Data Pack

Start working with Web services and live data instantly! The Super Data Pack brings together dozens of Web services into one easy-to-use “Super” Web service. With the Super Data Pack, developers and end-users can leverage multiple data sources for use within a diverse set of rich applications at no cost or with no commitment.

Featured Content provided by StrikeIron, Inc.

Juggling Identity in the Brave New World

25th Feb 06:

As we speed through the security industry’s gala ball—this week’s RSA Conference in San Jose—it’s clear that privacy and identity management are getting more attention than ever.

Over a period of ten years employed by RSA Security, I worked with authentication, access control, authorization, cryptography, Public Key Infrastructure (please buy my book on the subject, my retirement fund needs help), smart cards, and biometrics—all of those underlying technologies that in aggregate we refer to as Identity and Access Management.

With the rise of SOA and Web services, more and more valuable information is network accessible. XML is quietly invading our networks and applications. Guaranteeing the security, privacy and appropriate access to that information presents a significant challenge, so it has been a natural progression for me to engage in addressing solutions in this area.

Many enterprises have invested in Identity and Access Management. Today they are juggling multiple identity systems and are currently working hard to make Federated Identities effective. Much more than traditional applications, Web Services require leveraging identities, access control and privacy mechanisms effectively. The loosely coupled, reusable value propositions of SOA have significant implications for security policies as granular access to business services cross many trust boundaries.

Consistent and verifiable enforcement of policies must be maintained in the face of different authentication schemes, each with different identities and unique credential formats, different trust models, unique regulatory requirements and a selection of options within standards on particular platform implementations. And then you have to cope with changes in versions of everything. SOA requires a virtualization mechanism that reduces complexity, supports and simplifies change and provides enforcement and monitoring points for verifiable policy application.

Doing security right is expensive in a Web Services world. Mitigation of message-based attacks may require multiple credentials identifying intermediate services, as well as principals in the transaction. Integration with legacy systems may require aggregation of identity attributes and additional authentication credentials, whilst ensuring that the information is not revealed to intermediate systems. Privacy curtains may be required to guarantee that sensitive information sets are transformed, obfuscated, or removed as particular trust boundaries are crossed.

It is already clear that application platforms are grinding away progressively more slowly and the more of these security features we add, the worse the performance becomes. Acceleration and fast processing techniques are helping, but caching, reuse and system-wide optimization of security processing are essential in the brave new world of networked application systems.


Trackback URL for this post: http://www.webservices.org/trackback/id/72663

Comments