wisemonkeys logo
FeedNotificationProfileManage Forms
FeedNotificationSearchSign in
wisemonkeys logo

Blogs

Basic Security For SOAP Services

profile
Fatma Shaikh
Sep 20, 2022
0 Likes
0 Discussions
172 Reads

 BASIC SECURITY FOR SOAP SERVICES.

Simple Object Access Protocol (SOAP) is a network protocol for exchanging structured data between nodes. It uses XML format to transfer messages. It works on top of application layer protocols like HTML and SMTP for notations and transmission. SOAP allows processes to communicate throughout platforms, languages and operating systems, since protocols like HTTP are already installed on all platforms.

 

  • SOAP-Based Web Services.

SOAP is an API messaging protocol, and SOAP security is the strategy that prevents unauthorized access to SOAP messages and user information.    Web Standards Security (WS Security) is the main aspect of ensuring SOAP security.

SOAP was originally developed as a web service protocol, with an HTTP transport binding. At the same time, the designers of the protocol made sure that the SOAP specification was not dependent on any features of the underlying transport. As a result, SOAP can be used over a large number of transport protocols today, thus providing a consistent way of creating services over a number of different platforms. Such platforms include SMTP, FTP, and message queuing protocols. This flexibility does not come for free, though, since many transport semantics (such as session security, routing, acknowledgments, etc.) that are provided by the underlying transport protocols need to be replicated within the SOAP stack. This can lead to significant performance issues and replication of functionality at different layers.

 

  • WS-Security Overview.

SOAP is a messaging protocol, meaning that SOAP security is primarily concerned with preventing unauthorized access to these messages and to users’ information. The main thing used to accomplish this is WS (Web Standards) Security. 

WS Security is a set of principles that regulate the confidentiality and authentication procedures for SOAP messaging. WS Security-compliant measures include passengers, digital signatures and XML (Extensible Markup Language) encryption, among other things. XML encryption causes the data to be unreadable to unauthorized users. 

 

  • Protocol Design.

 

  • Usage of WS-Security.

 

WS-Security is only of limited use: it describes how security elements such as tokens and signatures can be incorporated into a SOAP message. It also provides limited instructions on how to protect portions of the message using these security elements.

 

  • Authentication With WS-Security.

 

A common use of WS-Security is for authentication of the incoming request. In order to process (an update to an account using a SOAP request), the bank service will need to verify the identity of the invoker (authentication) so that it can apply its authorization policies.

 

  • Attaching Policies to Web Services.

 

Authentication of a single request is achieved by providing the token within the security header. Since there are countless ways of doing this, the service needs to communicate to the client the type of acceptable tokens, acceptable configurations of these tokens, and how to protect them.

  • Example for a Web Service Definition Language for WS-Security.

An example given below shows a client talking to both a database and a web server at a time. In such cases, not all information can pass through the https protocol. This is where SOAP comes in action to overcome such obstacles by having the WS Security specification in place.

 


Comments ()


Sign in

Read Next

Improving defences Proxy Device(defense in depth)

Blog banner

Article on Zoho Corporation

Blog banner

Starvation

Blog banner

Compromising Mobile Platforms

Blog banner

Components of GIS

Blog banner

Simple STEM Activities for Toddlers That Spark Curiosity

Blog banner

Place to visit in pune

Blog banner

OPERATING SYSTEM OBJECTIVES AND FAULT TOLERENCE.

Blog banner

GIS in Disaster Management

Blog banner

Understanding Endometriosis and Its Psychological Impact on Quality of Life

Blog banner

What Your Music Taste Reveals About Your Personality

Blog banner

GOOGLE

Blog banner

Assignment-3

Blog banner

Ghee vs. Coconut Oil vs. Mustard Oil: Which Cooking Fat Wins for Indian Food?

Blog banner

Operating system

Blog banner

Texting is actually better than talking in person

Blog banner

IT RISK

Blog banner

Cache memory

Blog banner

Article on Fresh Book

Blog banner

All you need to know about Website Traffic

Blog banner

Best Time to Visit Arcadia, Florida & Why Oak Tree Hotel Is Always Ready

Blog banner

Vulnerability Assessment (Vulnerability Analysis)

Blog banner

Fitness

Blog banner

Cybersecurity Standards for Automotive

Blog banner

"The Benefits of Using GIS in Agriculture"

Blog banner

security controls

Blog banner

Evolution of Operating system.

Blog banner

The Future of Patola Weaving in a Sustainable Fashion World

Blog banner

Sleep Matters: The Science Behind Toddler Naps

Blog banner

Race Condition in Operating Theatre

Blog banner

The role of artificial intelligence in automating digital forensic analysis.

Blog banner

File Systems in OS.

Blog banner

A BLOG ON MYSQL

Blog banner

Palm Vein Biometric Technology; Contactless vein authentication

Blog banner

VIRTUAL MACHINE

Blog banner

TRAIN TRAVELING

Blog banner

How International Schools Build Global-Minded Students through Curriculum & Activities

Blog banner

Toothache Causes: Common Tooth Pain Reasons & When to See a Dentist

Blog banner

MEMORY FORENSIC ACQUISITION AND ANALYSISOF MEMORY AND ITS TOOLS COMPARISON

Blog banner

Does School Infrastructure Really Matter For Learning?

Blog banner

From Model Mistakes to Metrics

Blog banner

Understanding E-mail Servers

Blog banner