Download presentation
Presentation is loading. Please wait.
1
WS-SecureConversation
Vidya Iyer 3/11/06
2
Web services
4
SecureConversation End-to-end security Leverages SSL, and Kerberos
Leverages XMLENC and XMLDSIG Establishes contexts for convenient multi-message communication Initial overhead to establish context, then faster communication
5
Terms Security Token – security related information (ie. X.509 cert, Kerberos ticket, username) Security Context – established authenticated state, and related keys Security Context Token – URI representation of Security Context
6
Creating Secure Contexts
7
Changing contexts Amending, Renewing, Cancel contexts
Requester sends Amend URI And proof of possession of key Recipients authenticate request and update their context Same for Renew, Cancel
8
Deriving keys Common to use SecureContexts to agree on pseudorandom generators to derive keys Uses DeriveKeyToken syntax Syntax is agnostic to key derivation scheme No need to send key material
9
Benefits over SSL End-to-end security XML aware Selective encryption
Easier to nullify existing contexts
10
Questions?
Similar presentations
© 2025 SlidePlayer.com Inc.
All rights reserved.