教学文库网 - 权威文档分享云平台
您的当前位置:首页 > 文库大全 > 小学教育 >

信息系统外文翻译

来源:网络收集 时间:2026-10-01
导读: 外文翻译 08信管(2)班 Xc08540214 张力炯 原文1 Verifying Policy-Based Web Services Security SECURITY POLICIES FOR WEB SERVICES 1 Web Services and XML Rewriting Attacks We consider systems of SOAP processors distributed across multiple machin

外文翻译

08信管(2)班 Xc08540214 张力炯

原文1

Verifying Policy-Based Web Services Security

SECURITY POLICIES FOR WEB SERVICES

1 Web Services and XML Rewriting Attacks

We consider systems of SOAP processors distributed across multiple machines. The primitive message pattern is asynchronous communication of a single SOAP message from one processor to another. A common derived message pattern is a request-response protocol between a client and a server. A single SOAP processor (e.g., a web server) may act both as a client and a server. For example, acting as a server, it may receive a request and then, acting as a client of another server, send a new request and use the subsequent response to construct its response to the original request.

Each SOAP message conforms to an XML schema for an envelope, comprising an optional header element for routing, security, and other metadata, plus a mandatory body element containing the message payload. For instance, here is a simple (unprotected) envelope.

<Envelope>

<Header>

<To>http://www.77cn.com.cn/service.asmx</To>

<Action>http://petshop/premium</Action>

<MessageId>uuid: 5ba86b04...</MessageId>

</Header>

<Body>

<GetOrder><orderId>20</orderId></GetOrder>

</Body>

</Envelope>

We treat SOAP faults as ordinary SOAP responses. For the sake of read-ability,

our presentation omits many details of the XML wire format, such as XML namespace information, and uses an abstract syntax for policies and configurations. Our formalism retains many details of the XML syntax, as they matter for security; for example, an XML signature may cover some chosen subset of the SOAP headers, so our model needs to represent the various headers. Even though our formalism hides some of the XML details, our tools directly consume and produce the XML file formats used by WSE.

There is a risk, of course, that SOAP messages may be read in transit by a passive attacker able to read network traffic. Moreover, SOAP messages may be created, modified, and replayed by an active attacker able to inject messages into the network. (In fact, the flexibility and explicitness of SOAP messages also make such attacks easier to set up.) The usual solution is to secure messages with cryptography. The details are subtle. The incorrect use of cryptography may leave vulnerabilities open to attack, as described by Needham and Schroeder [1978]. The conservative recommendation of Needhamand Schroeder is that the security goals of protocols based on cryptography should be established even in the presence of a demanding adversary: one who is in control of the network, has the use of some of the cryptographic keys belonging to principals of the system, and may employ these keys in attacks against other principals.

2 WS-Security

As we discuss elsewhere [Bhargavan et al. 2005a], WS-Security provides a precise grammar and default processing for elements in the security header, but prescribes no fixed protocol itself.Hence,compared to traditional transport security, WS-Security is more flexible, yet more costly in terms of performance and complexity.

In this article, we consider two representative sorts of security token; the standard defines several others. An X.509 token supports XML encryption and signature based on public-key cryptography. It is an XML element whose convent is an encoding of an X.509 certificate, a binary format including a subject name and a public key, jointly signed by a private key of some certification authority.

A username token [Nadalin et al. 2004a] supports XML signature based on password sharing. It is an XML element that always includes a username and may include other elements such as a timestamp and a nonce. Provided sender and receiver know the password associated with the username, they can derive a shared symmetric

key from the token by hashing the password with the timestamp and nonce, and then use this key to produce and verify the MAC embedded in the signature. The mechanism for key derivation is left unspecified in the standard. For concreteness, we follow the WSE implementation, which uses the P SHA1 function defined in TLS

[Dierks and Rescorla 2006] to derive keys that are used for message authentication—but not for encryption. However, this does not reflect a limitation in our formalism or analyses, which can be used to model both signature and encryption using a variety of key derivation algorithms.

We assume a population of known principals, principals able to authenticate their identity via passwords or public keys. For simplicity, principals are identified by their name, as it appears in security tokens: the subject field in X.509 certificates, and the username element in username tokens. We let names range over arbitrary strings. We say a security token is known if it is recognized by the system. An X.509 token is known if the underlying X.509 certificate is issued by an acceptable certification authority. A username token is known if the corresponding username and password are registered in the password database. Not all known principals are trusted to keep their cryptographic materials secret (see Section 3.4).

作者:Karthikeyan Bhargavan,Cédric Fournet,Andrew D. Gordon

国籍:英国

出处:Verifying policy-based security for web services

译文1

验证基于策略的Web服务安全性

Web服务的安全策略

1. Web服务和XML重写攻击

我们认为SOAP处理器系统分布在多台机器。原始消息模式是从发送端到接收端的单向异步传输。一个共同产生的信息模式是服务器120和客户端之间的一个请求响应协议。一个单一的SOAP处理器(例如, Web服务器)可能扮演客户端和服务器的双重角色。举例来说,作为服务器,它可能会收到一个请求;而作为另一台服务器的客户端,它发送新的请求并使用随后的响应去构建针对原来请求的响 …… 此处隐藏:18433字,全部文档内容请下载后查看。喜欢就下载吧 ……

信息系统外文翻译.doc 将本文的Word文档下载到电脑,方便复制、编辑、收藏和打印
本文链接:https://www.jiaowen.net/wenku/1542830.html(转载请注明文章来源)
Copyright © 2020-2025 教文网 版权所有
声明 :本网站尊重并保护知识产权,根据《信息网络传播权保护条例》,如果我们转载的作品侵犯了您的权利,请在一个月内通知我们,我们会及时删除。
客服QQ:78024566 邮箱:78024566@qq.com
苏ICP备19068818号-2
Top
× 游客快捷下载通道(下载后可以自由复制和排版)
VIP包月下载
特价:29 元/月 原价:99元
低至 0.3 元/份 每月下载150份
全站内容免费自由复制
VIP包月下载
特价:29 元/月 原价:99元
低至 0.3 元/份 每月下载150份
全站内容免费自由复制
注:下载文档有可能出现无法下载或内容有问题,请联系客服协助您处理。
× 常见问题(客服时间:周一到周五 9:30-18:00)