计算机与现代化 ›› 2012, Vol. 208 ›› Issue (12): 114-118.doi: 10.3969/j.issn.1006-2475.2012.12.030

• 信息安全 • 上一篇    下一篇

支持多密级的SOAP消息安全模型研究与实现

胡杰青,王福喜,徐东华   

  1. 华北计算技术研究所,北京100083
  • 收稿日期:2012-07-27 修回日期:1900-01-01 出版日期:2012-12-22 发布日期:2012-12-22

Research and Implementation of SOAP Multilevel Security Model

HU Jie-qing, WANG Fu-xi, XU Dong-hua   

  1. North China Institute of Computing Technology, Beijing 100083, China
  • Received:2012-07-27 Revised:1900-01-01 Online:2012-12-22 Published:2012-12-22

摘要: 为了实现多密级、特殊密码环境下的Web服务安全性,在对WS-Security规范进行研究的基础上对其进行修改和扩展,提出支持多密级SOAP消息安全标识扩展协议和SOAP消息多密级安全协议,设计并实现一个基于上述协议的SOAP消息安全模型,该模型利用多密级密码服务接入技术,根据安全标识实现支持多密级的SOAP消息安全性要求,从而验证多密级安全协议的完整性、可用性。

关键词: 多密级, 简单对象访问协议, Web服务安全, XML签名, XML加密

Abstract: In order to realize the Web services security in the multilevel security and special cipher environment, based on the modification and expansion of WS-Security specification, SOAP multilevel security polices expand protocol and SOAP multilevel security protocol are proposed, and SOAP security model based on the above protocols is designed and implemented. Relying on the use of multilevel cipher services access technology, this model uses security polices to ensure the SOAP multilevel security. Using the model can validate the integrity and availability of above protocols.

Key words: multilevel security, SOAP, WS-Security, XML-Signature, XML-Encryption

中图分类号: