Security protocol has lots of work ahead of it

Opinion
May 4, 20052 mins

* WS-Security

Security protocol has lots of work ahead of it

By John Fontana

The security protocol that began to increase use of Web services on corporate networks is now a year old: WS-Security has firmly established itself as a foundation IT can trust for securing XML-based traffic, according to analysts and the specification’s co-author.

The protocol, which became a formal standard in April 2004, has become so widely accepted that it is now seen as a core Web services protocol along with the Simple Object Access Protocol and the Web Services Description Language.

But despite that acceptance, experts say that the changing landscape around Web services and service-oriented architectures means there is much more work to be done.

WS-Security provides a general-purpose method for building integrity, confidentiality and authentication into the message exchange that permeates any communication among Web services applications. The protocol integrates technology used to secure messages, including X.509 certificates and Kerberos.

What WS-Security solves for end users is the question of how to pass data securely between Web services, which was a showstopper until IBM, Microsoft and VeriSign proposed WS-Security and a slate of six extensions in 2002. The protocol eventually was submitted to the Organization for the Advancement of Structured Information Standards, which made it a standard last year. But the extensions haven’t progressed to a standards track; they represent the next level of sophistication for the protocol.

“The uptake is that WS-Security is becoming the de facto standard for message-level security in Web services,” says Tony Nadalin, the co-author of WS-Security and IBM’s chief security architect. “We see vendors, such as XML firewall vendors, using this as a way to get message-level protection. We see the application server vendors, IBM, Microsoft, BEA and others, starting to put this into the stack in their Web services implementations.”

Last month 13 vendors, including IBM, Microsoft, Oracle and Sun, staged a WS-Security interoperability test to prove that their implementations would interoperate.

For the full story, please go to:

http://www.networkworld.com/news/2005/050205-ws-security.html?nlt

For questions or comments regarding this newsletter’s content, contact Newsletter Editor Jeff Caruso at mailto:jcaruso@nww.com