OASIS Approves New Web Services Security Standards

March 28, 2007

The Organization for the Advancement of Structured Information Systems has approved WS-SecureConversation and WS-Trust as standards.

The Organization for the Advancement of Structured Information Systems has announced that its members have approved WS-SecureConversation version 1.3 and WS-Trust version 1.3 as OASIS Standards.

The specifications were developed by the OASIS WS-SX (Web Services Secure Exchange) Technical Committee and they define policies and extensions to WS-Security that enable the trusted exchange of multiple SOAP (Simple Object Access Protocol) messages.

WS-Trust provides methods for issuing, renewing and validating security tokens as well as establishing, detecting and brokering trust relationships, OASIS officials said. Meanwhile, WS-SecureConversation allows security contexts to be created and key material to be exchanged more efficiently, OASIS said.

Together the standards can improve the performance and security of exchanges.

"In order to secure communication between two parties, both must exchange security credentials," said Anne Thomas Manes, research director with the Burton Group, in a statement.

"Before that can take place though, each party needs to determine if they can 'trust' the asserted credentials of the other. Applications that communicate using the Web services framework (e.g., SOAP and WSDL) can use WS-Trust to obtain and exchange security credentials - either directly or through a trusted third party - and use WS-SecureConversation to establish and maintain an extended secure session."

Kelvin Lawrence of IBM, co-chair of the OASIS WS-SX Technical Committee, said, "WS-Trust builds upon WS-Security by introducing an XML syntax and a protocol that enables the issuance and dissemination of credentials between different trust domains via a security token service."

Meanwhile, Chris Kaler, a Microsoft engineer and co-chair of the WS-SX committee, said, "WS-Security focuses on the security of a single message, which is useful in many situations. WS-SecureConversation adds a security context authentication model that is extremely beneficial for long-running exchanges. When two parties are passing multiple rounds of secured messages back and forth, the added security and efficiency provided by WS-SecureConversation becomes essential."

Among the industry leaders, IBM, Microsoft and Sun Microsystems have verified successful implementations of WS-SecureConversation and WS-Trust in accordance with eligibility requirements for all OASIS Standards.

However, Adobe, AmberPoint, Axway, BEA Systems, BMC Software, CA, EDS, Forum Systems, Fujitsu, HP, IBM, IONA, Microsoft, Neustar, Nokia, Nortel, Novell, Oracle, Progress Software, Red Hat, Ricoh, SAP, SOA Software, Software AG, Sun Microsystems, Tibco Software, VeriSign, and other members of OASIS collaborated to develop WS-SecureConversation and WS-Trust, OASIS officials said.

Copyright 2007 by Ziff Davis Media, Distributed by United Press International


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - not rated yet


March 28, 2007 all stories

Comments: 0

not rated yet
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Saudi aims for moon with new hi-tech research oasis
    created Sep 23, 2009 | popularity not rated yet | comments 0
  • The Web: Tools that manage app access
    created Sep 21, 2005 | popularity not rated yet | comments 0
  • Gadgets: Card reader helps you shop safer online
    created 14 minutes ago | popularity not rated yet | comments 0
  • Early relationships influence teen pain and depression
    created Nov 25, 2009 | popularity not rated yet | comments 0
  • Modified iPhones Are Compromised By New Worm
    created Nov 25, 2009 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Achromat lens - magnifying LCD
    created 17 hours ago
  • Control System
    created Nov 24, 2009
  • Base Isolation Systems in Skyscrapers?
    created Nov 23, 2009
  • Need to interview a Computer Hardware Engineer for school project
    created Nov 23, 2009
  • More from Physics Forums - General Engineering

Other News

Holiday Web shopping looks brighter than last year

Technology / Internet

created 1hour ago | popularity not rated yet | comments 0

(AP) -- Online retailers hope the convenience of the Web, plus discounts and deals, spur still-nervous shoppers to spend more online this holiday season - even as traditional retailers brace for mediocre sales.


Sony optimistic on 3-D TVs, in-house display (AP)

Sony optimistic on 3-D TVs, in-house display

Technology / Hi Tech

created 5 hours ago | popularity not rated yet | comments 0

(AP) -- A third to a half of the Sony Corp. TV sets sold annually will be packed with 3-D features by the year ending March 2013, a senior executive said Thursday.


The goal of robot hockey: to become better engineers

The goal of robot hockey: to become better engineers (w/ Video)

Technology / Engineering

created 3 hours ago | popularity not rated yet | comments 0

(PhysOrg.com) -- It may be a long time before we see robots shooting pucks and making saves in professional hockey, but second-year mechanical engineering students at the University of Alberta put some pretty ...


Should I buy a PC or Mac?

Technology / Software

created 16 hours ago | popularity 4.2 / 5 (5) | comments 9

Q. Our 6-year-old PC computer is dying a slow death and we are considering moving to a new iMac but have a few concerns. First, of all, we have several Word documents on our disk drive now that we want to keep and add to ...


Post Office card error leaves Italians in the red: report

Technology / Other

created 5 hours ago | popularity 4 / 5 (1) | comments 0

A computer glitch left Italian Post Office customers in the red by processing card transactions at 100 times their value, Italian press reported Thursday.