信息系统外文翻译
外文翻译
08信管(2)班 Xc08540214 张力炯
原文1
Verifying Policy-Based Web Services Security
SECURITY POLICIES FOR WEB SERVICES
1 Web Services and XML Rewriting Attacks
We consider systems of SOAP processors distributed across multiple machines. The primitive message pattern is asynchronous communication of a single SOAP message from one processor to another. A common derived message pattern is a request-response protocol between a client and a server. A single SOAP processor (e.g., a web server) may act both as a client and a server. For example, acting as a server, it may receive a request and then, acting as a client of another server, send a new request and use the subsequent response to construct its response to the original request.
Each SOAP message conforms to an XML schema for an envelope, comprising an optional header element for routing, security, and other metadata, plus a mandatory body element containing the message payload. For instance, here is a simple (unprotected) envelope.
<Envelope>
<Header>
<To>http://www.77cn.com.cn/service.asmx</To>
<Action>http://petshop/premium</Action>
<MessageId>uuid: 5ba86b04...</MessageId>
</Header>
<Body>
<GetOrder><orderId>20</orderId></GetOrder>
</Body>
</Envelope>
We treat SOAP faults as ordinary SOAP responses. For the sake of read-ability,
our presentation omits many details of the XML wire format, such as XML namespace information, and uses an abstract syntax for policies and configurations. Our formalism retains many details of the XML syntax, as they matter for security; for example, an XML signature may cover some chosen subset of the SOAP headers, so our model needs to represent the various headers. Even though our formalism hides some of the XML details, our tools directly consume and produce the XML file formats used by WSE.
There is a risk, of course, that SOAP messages may be read in transit by a passive attacker able to read network traffic. Moreover, SOAP messages may be created, modified, and replayed by an active attacker able to inject messages into the network. (In fact, the flexibility and explicitness of SOAP messages also make such attacks easier to set up.) The usual solution is to secure messages with cryptography. The details are subtle. The incorrect use of cryptography may leave vulnerabilities open to attack, as described by Needham and Schroeder [1978]. The conservative recommendation of Needhamand Schroeder is that the security goals of protocols based on cryptography should be established even in the presence of a demanding adversary: one who is in control of the network, has the use of some of the cryptographic keys belonging to principals of the system, and may employ these keys in attacks against other principals.
2 WS-Security
As we discuss elsewhere [Bhargavan et al. 2005a], WS-Security provides a precise grammar and default processing for elements in the security header, but prescribes no fixed protocol itself.Hence,compared to traditional transport security, WS-Security is more flexible, yet more costly in terms of performance and complexity.
In this article, we consider two representative sorts of security token; the standard defines several others. An X.509 token supports XML encryption and signature based on public-key cryptography. It is an XML element whose convent is an encoding of an X.509 certificate, a binary format including a subject name and a public key, jointly signed by a private key of some certification authority.
A username token [Nadalin et al. 2004a] supports XML signature based on password sharing. It is an XML element that always includes a username and may include other elements such as a timestamp and a nonce. Provided sender and receiver know the password associated with the username, they can derive a shared symmetric
key from the token by hashing the password with the timestamp and nonce, and then use this key to produce and verify the MAC embedded in the signature. The mechanism for key derivation is left unspecified in the standard. For concreteness, we follow the WSE implementation, which uses the P SHA1 function defined in TLS
[Dierks and Rescorla 2006] to derive keys that are used for message authentication—but not for encryption. However, this does not reflect a limitation in our formalism or analyses, which can be used to model both signature and encryption using a variety of key derivation algorithms.
We assume a population of known principals, principals able to authenticate their identity via passwords or public keys. For simplicity, principals are identified by their name, as it appears in security tokens: the subject field in X.509 certificates, and the username element in username tokens. We let names range over arbitrary strings. We say a security token is known if it is recognized by the system. An X.509 token is known if the underlying X.509 certificate is issued by an acceptable certification authority. A username token is known if the corresponding username and password are registered in the password database. Not all known principals are trusted to keep their cryptographic materials secret (see Section 3.4).
作者:Karthikeyan Bhargavan,Cédric Fournet,Andrew D. Gordon
国籍:英国
出处:Verifying policy-based security for web services
译文1
验证基于策略的Web服务安全性
Web服务的安全策略
1. Web服务和XML重写攻击
我们认为SOAP处理器系统分布在多台机器。原始消息模式是从发送端到接收端的单向异步传输。一个共同产生的信息模式是服务器120和客户端之间的一个请求响应协议。一个单一的SOAP处理器(例如, Web服务器)可能扮演客户端和服务器的双重角色。举例来说,作为服务器,它可能会收到一个请求;而作为另一台服务器的客户端,它发送新的请求并使用随后的响应去构建针对原来请求的响 …… 此处隐藏:18433字,全部文档内容请下载后查看。喜欢就下载吧 ……
相关推荐:
- [小学教育]四年级综合实践活动课《衣物的洗涤》教
- [小学教育]2014半年工作总结怎么写
- [小学教育]20世纪外国文学专题综合试题及答案
- [小学教育]TS_1循环使用催化丙烯环氧化反应研究
- [小学教育]最实用的考勤签到表(上下班签到表)
- [小学教育]气候与生态建筑——以新疆民居为例
- [小学教育]二人以上股东有限责任公司章程参考样本
- [小学教育]2014届第一轮复习资料4.1,3美好生活的
- [小学教育]土方开挖、降水方案
- [小学教育]手绘儿童绘本《秋天的图画》(蜡笔)
- [小学教育]2002级硕士研究生卫生统计学考试试题
- [小学教育]环保装备重点发展目录
- [小学教育]金蝶K3合并报表培训教材
- [小学教育]岩浆岩试题及参考答案
- [小学教育]知之深爱之切学习心得
- [小学教育]第十二章 蛋白质的生物合成
- [小学教育]Chapter 2-3 Solid structure and basi
- [小学教育]市政道路雨季专项施工方案
- [小学教育]中国海洋大学2012-2013学年第二学期天
- [小学教育]教育心理学第3章-学习迁移
- 浅谈深化国企改革中加强党管企业
- 2006年中国病理生理学会学术活动安排
- 设计投标工作大纲
- 基于ARP的网络攻击与防御
- 2016届湖北省七市(州)教科研协作体高三
- Google_学术搜索及其检索技巧
- 2019-2020学年七年级地理下册6.3美洲教
- 城市道路可研报告
- 【名师指津】2012高考英语 写作基础技
- 6级知识点培训北京师范大学《幼儿智趣
- 注册会计师会计知识点:金融资产
- 新安装 500 kV 变压器介损分析与判断
- PS2模拟器PCSX2设置及使用教程.
- 医院药事管理与药剂科管理组织机构
- {PPT背景素材}丹巴的醉人美景,免费,一
- NAS网络存储应用解决方案
- 青海省西宁市六年级上学期数学期末考试
- 测量管理体系手册依据ISO10012:2003
- 洞子小学培养骨干教师工作计划
- 浅谈《牛津初中英语》的教材特点及教学




