Security is playing an increasingly important role in nowadays business. However, at present there isn?t an effective method to secure SOAP attachments. This paper proposes a novel security model for SOAP attachments, which encrypts the attachments and provides digital signature without changing client?s and server?s implementations. In the multi-intermediaries scenario, the whole message is divided into two parts and sent respectively: the primary part goes through as the original message path via intermediaries, while the attachments are sent directly from client to server via no intermediary. Therefore, it improves the efficiency of services and reduces the probability of the attachments' being attacked. A prototype of this security model is implemented on the Web application server and the experiment results show the feasibility of secure attachments in enterprise applications.
Citation:
Xiaoling Cui, Lei Li, Jun Wei, "A Novel SOAP Attachment-Oriented Security Model," issre, pp.127-135, 17th International Symposium on Software Reliability Engineering (ISSRE'06), 2006