OpenAjax Alliance Delivers Software for More Secure Enterprise Mashups

August 31, 2009

The OpenAjax Alliance announced today the approval and availability of OpenAjax Hub 2.0 as an industry standard for more secure Web 2.0 mashup applications. Advances in security in Hub 2.0 can help protect enterprise mashups from malicious intent, giving IT staff greater confidence in adding these features to their Web sites.

OpenAjax Hub 2.0 was developed over the past two years at OpenAjax Alliance, an organization dedicated to the adoption of open and interoperable Ajax technologies. Ajax is Web development technology based on HTML and JavaScript that runs mashups, widgets and gadgets. Mashups allow business users to drag and drop "mashed up" components to create customized Web applications in minutes.

The major addition to Hub 2.0 is a JavaScript Library for Secure Enterprise Mashups created to better protect widgets and mashups from hackers and malicious intent. It addresses concerns among IT managers that may have inhibited adoption of mashup software within companies.

"OpenAjax Hub 2.0 is a major step forward for the OpenAjax Alliance towards its mission of promoting Ajax interoperability," says David Boloker, OpenAjax Alliance Steering Committee chairman and chief technology officer for Emerging , IBM. "In order to realize the potential for mashups across the industry, there needs to be standards. Hub 2.0 defines a key industry standard for how widgets can be isolated into secure containers and then how widgets can talk to each other through a mediated messaging bus."

Hub 2.0 isolates third-party widgets into secure sandboxes and mediates messaging among the widgets with a security manager. For example, suppose a Web site includes a third-party calendar widget. That widget itself might be malicious or might become malicious if its code has vulnerabilities that allow a site to hijack the widget. Malicious widgets could transmit hijacked data to a scamming web site or piggyback user credentials to read and write from company servers.

Hub 2.0 prevents attacks by isolating untrusted widgets from the main application and other widgets, and by preventing access to user credentials. It protects against widget hijacking due to its features around careful widget loading and unloading and message integrity.

An Overview of OpenAjax Hub 2.0

Hub 2.0 consists of two main parts, a specification and an open source implementation.

• The Hub 2.0 Specification has been recently approved by the members of OpenAjax Alliance as an Ajax industry standard. The specification defines standardized JavaScript APIs for secure mashups and will result in cross-vendor interoperability among mashup tools and mashup components.

• The alliance has also developed an open source implementation of the Hub 2.0 specification. The open source implementation is written in browser JavaScript and is compatible with all popular desktop browsers.

This announcement is part of a broader set of initiatives at OpenAjax Alliance to accelerate customer success using Ajax. In addition to OpenAjax Hub, the alliance is working on a companion mashup initiative, OpenAjax Widgets, which defines an Ajax interoperability standard for Ajax widgets, and is scheduled for approval in the coming months.

OpenAjax Hub 2.0 was validated in late 2008 during a multi-vendor interoperability event, and then revised in early 2009 to allow straightforward integration with other industry mashup technologies, particularly OpenSocial technologies. It has now been finalized and approved for release.

Hub 2.0 also includes a comprehensive test suite and provides an extensibility architecture that allows software vendors and enterprise customers to customize and extend to meet particular needs. The specification and open source have been designed with enterprise performance requirements in mind. The Hub 2.0 technology includes a fast-performance option for trusted widgets (e.g., widgets developed by the company's own IT department) which allows internal company mashups at scale. The security features in Hub 2.0 build from the Secure Mashup (SMash) open source contribution from IBM Research to OpenAjax Alliance that was announced in 2008.

To help vendors deploy Hub 2.0, the alliance has written two white papers:

• "Introducing OpenAjax Hub 2.0 and Secure Mashups" http://www.openajax.org/whitepapers/Introducing%20OpenAjax%20Hub%202.0%20and%20Secure%20Mashups.php
• "OpenAjax Hub 2.0 and Mashup Assembly Applications" http://www.openajax.org/whitepapers/OpenAjax%20Hub%202.0%20and%20Mashup%20Assembly%20Applications.php
The alliance also has developed an open source mashup assembly application that showcases how to create a browser-based mashup application that uses OpenAjax Hub 2.0 and OpenAjax as the key technologies within the application.

The OpenAjax Alliance is an organization of vendors, projects and companies using Ajax that are dedicated to the successful adoption of open and interoperable Ajax-based Web technologies. OpenAjax members include more than 100 organizations including Adobe, the Eclipse Foundation, Google, IBM and Microsoft working towards the mutual goal of accelerating customer success with Ajax. To learn more about OpenAjax Alliance, please visit, www.openajax.org .

Source: IBM


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 5 /5 (2 votes)


August 31, 2009 all stories

Comments: 0

5 /5 (2 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • IBM Cracks Web 2.0 Security Concerns With 'SMash'
    created Mar 13, 2008 | popularity not rated yet | comments 0
  • IBM Advances Web 2.0 Platform for Business
    created Jan 23, 2008 | popularity not rated yet | comments 0
  • Web sites get cool with Ajax or die
    created Jun 15, 2006 | popularity not rated yet | comments 0
  • Microsoft Tool Lets the Masses Create Apps, Web Pages
    created May 19, 2007 | popularity not rated yet | comments 0
  • Intel and Yahoo! to Bring the Internet to Television
    created Aug 20, 2008 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • transient heat transfer
    created 6 hours ago
  • Trying to adapt a fuel gage circuit
    created 23 hours ago
  • Pushing the piston.
    created Nov 22, 2009
  • Do Camcorders/ Video camera have Sensors in them?
    created Nov 22, 2009
  • Aspiring Engineering major looking for general answers
    created Nov 19, 2009
  • Calculating max load of square tube (steel)
    created Nov 19, 2009
  • More from Physics Forums - General Engineering

Other News

Just in time for Black Friday: students turn iPhone into barcode scanner

Just in time for Black Friday: students turn iPhone into barcode scanner

Technology / Software

created 15 minutes ago | popularity not rated yet | comments 0

(PhysOrg.com) -- Comparing prices over the Internet has become a common practice for consumers. Now, just in time for Black Friday, a group of Missouri University of Science and Technology students is putting ...


IBM Researchers Lower Language Barrier With Text Translator

Technology / Computer Sciences

created 2 hours ago | popularity 4 / 5 (1) | comments 0

IBM Researchers are helping to break the language barrier with the advent of technology dubbed "n.Fluent" -- smart software that translates text between English and 11 other languages. IBM employees use it to instantaneously ...


Friends go online at Foursquare to meet offline (AP)

Friends go online at Foursquare to meet offline

Technology / Internet

created 2 hours ago | popularity not rated yet | comments 0

(AP) -- Laura Fitton's ascent has been staggering: In less than a year, she's become mayor of nine different places in several different states, all without giving any speeches or kissing any babies.


HP's profit up 14 pct despite sales drop (AP)

HP's profit up 14 pct despite sales drop

Technology / Business

created 2 hours ago | popularity not rated yet | comments 0

(AP) -- Hewlett-Packard Co.'s profit jumped 14 percent in the latest quarter, helped by cost-cutting and better results from its technology services division.


Intel logo A

Intel wants a chip implant in your brain

Technology / Hi Tech

created 12 hours ago | popularity 4.1 / 5 (15) | comments 26

(PhysOrg.com) -- Computer chip maker Intel wants to implant a brain-sensing chip directly into the brains of its customers to allow them to operate computers and other devices without moving a muscle.