Re: XML protocol security

It would be useful to list some of the requirements for secure XML
messaging. Here are some thoughts and I invite other contributions. 
 
1. 
The most important aspect seems to be that the protocol
itself be security neutral but support enough flexibility (using headers
for example) to incorporate a range of security arrangements. At first
glance,
this seems to be the case for SOAP where there is no hard-wired security
but there is support for a flexible set of headers which could presumably
express
security properties of the message (and those required of its response, if
any).
 
2. 
XML messaging will be used in many different environments, with security
needs ranging from none to requiring authentication, privacy thru
encryption,
message integrity, non-repudiation, secure acknowledgement, etc.  
The binding between security properties and the SOAP RPC call needs to
remain fairly loose. The same method call may be exposed with
varying security properties to different classes of users from within an
organization.
 
3. 
XML messaging can utilize many transports. Historically, some security
methods have been developed in the context of a transport (SSL, HTTP digest
authentication, S/MIME). It should be possible to utilize this type of
"off-the-shelf"
security.
 
4.
There is a strong consensus around the Role-Based Access Control (RBAC)
model as providing a scalable framework for enterprise security. This is
reflected
in the security architecture for EJBs , academic and industrial research
(NIST,
Sandhu research) and in commercial systems (Netegrity, enCommerce). 
The ACL approach is not considered scalable in an enterprise context where
there are many 1000's of users. This needs to be factored in when developing
an access control model for XML messaging.
 
 
- prateek mishra
Netegrity, Inc.
Waltham, MA
 
 
disclaimer: these are my personal opinions, not my employers.
 

Received on Wednesday, 17 May 2000 16:07:46 UTC