Securing Web Services With Ws-Security: Demystifying Ws-Security, Ws-Policy, Saml, Xml Signature, and Xml Encryption
暫譯: 使用 Ws-Security 確保網路服務安全:揭開 Ws-Security、Ws-Policy、SAML、XML 簽名與 XML 加密的神秘面紗
Jothy Rosenberg, David Remy
買這商品的人也買了...
-
$980$774 -
$1,029Operating System Concepts, 6/e (Windows XP Update)
-
$1,176Database Management Systems, 3/e (IE-Paperback)
-
$590$466 -
$680$537 -
$750$638 -
$560$476 -
$2,370$2,252 -
$850$723 -
$280$218 -
$480$379 -
$750$593 -
$780$616 -
$780$663 -
$590$460 -
$680$537 -
$490$382 -
$820$738 -
$620$484 -
$1,176Computer Organization and Design: The Hardware/Software Interface, 3/e(IE) (美國版ISBN:1558606041)
-
$480$408 -
$890$703 -
$650$507 -
$720$569 -
$400$340
相關主題
商品描述
The most up to date, comprehensive, and practical guide to Web services security, and the first to cover the final release of new standards SAML 1.1 and WS-Security.
- Comprehensive coverage and practical examples of the industry standards XML Signature and XML Encryption, and the first book to cover the final WS-Security and SAML 1.1 specifications.
- Authors Jothy Rosenberg and David Remy are security experts who co-founded GeoTrust, the #2 Web site certificate authority and currently work for Service Integrity and BEA Systems, respectively.
- According to IBM, American Express, Sun Microsystems, and other industry leaders, well-defined security standards and procedures are a crucial element to the adoption of web services in industry
-
Table of Contents
Forewords.
-
Introduction.
Who This Book Is For. About This Book. How This Book Is Organized.1. Basic Concepts of Web Services Security.
Web Services Basics: XML, SOAP, and WSDL. Application Integration. Security Basics. Web Services Security Basics. Summary.2. The Foundations of Web Services.
The Gestalt of Web Services. XML: Meta-Language for Data-Oriented Interchange. SOAP: XML Messaging and Remote Application Access. WSDL: Schema for XML/SOAP Objects and Interfaces. UDDI: Publishing and Discovering Web Services. ebXML and RosettaNet: Alternative Technologies for Web Services. The Web Services Security Specifications. Summary.3. The Foundations of Distributed Message-Level Security.
The Challenges of Information Security for Web Services. Shared Key Technologies. Public Key Technologies. Summary.4. Safeguarding the Identity and Integrity of XML Messages.
Introduction To and Motivation for XML Signature. XML Signature Fundamentals. XML Signature Structure. XML Signature Processing. The XML Signature Elements. Security Strategies for XML Signature. Summary.5. Ensuring Confidentiality of XML Messages.
Introduction to and Motivation for XML Encryption. XML Encryption Fundamentals. XML Encryption Structure. XML Encryption Processing. Using XML Encryption and XML Signature Together. Summary.6. Portable Identity, Authentication, and Authorization.
Introduction to and Motivation for SAML. How SAML Works. Using SAML with WS-Security. Applying SAML: Project Liberty. Summary.7. Building Security into SOAP.
Introduction to and Motivation for WS-Security. Extending SOAP with Security. Security Tokens in WS-Security. Providing Confidentiality: XML Encryption in WS-Security. Providing Integrity: XML Signature in WS-Security. Message Time Stamps. Summary.8. Communicating Security Policy.
WS-Policy. The WS-Policy Framework. WS-SecurityPolicy. Summary.9. Trust, Access Control, and Rights for Web Services.
The WS-* Family of Security Specifications. XML Key Management Specification (XKMS). eXtensible Access Control Markup Language (XACML) Specification. eXtensible Rights Markup Language (XrML) Management Specification. Summary.10. Building a Secure Web Service Using BEA's WebLogic Workshop.
Security Layer Walkthrough. WebLogic Workshop Web Service Walkthrough. Summary.Appendix A. Security, Cryptography, and Protocol Background Material.
The SSL Protocol. Testing for Primality. RSA Cryptography. DSA Digital Signature Algorithms. Block Cipher Processing. DES Encryption Algorithm. AES Encryption Algorithm. Hashing Details and Requirements. SHA1. Silvio Micali's Fast Validation/Revocation. Canonicalization of Messages for Digital Signature Manifests. Base-64 Encoding. PGP.Glossary.
Index
商品描述(中文翻譯)
《網路服務安全的最新、全面且實用的指南,首次涵蓋新標準 SAML 1.1 和 WS-Security 的最終版本。》
- 全面涵蓋並提供行業標準 XML 簽名和 XML 加密的實用範例,並且是第一本涵蓋最終 WS-Security 和 SAML 1.1 規範的書籍。
- 作者 Jothy Rosenberg 和 David Remy 是安全專家,曾共同創立 GeoTrust,該公司是第二大網站證書授權機構,目前分別在 Service Integrity 和 BEA Systems 工作。
- 根據 IBM、美國運通、Sun Microsystems 和其他行業領導者的說法,明確定義的安全標準和程序是行業採用網路服務的關鍵要素。
### 目錄
**前言。**
**介紹。**
- 本書的讀者。關於本書。本書的組織結構。
**1. 網路服務安全的基本概念。**
- 網路服務基礎:XML、SOAP 和 WSDL。應用整合。安全基礎。網路服務安全基礎。總結。
**2. 網路服務的基礎。**
- 網路服務的整體觀。XML:數據導向交換的元語言。SOAP:XML 訊息和遠端應用存取。WSDL:XML/SOAP 物件和介面的架構。UDDI:發布和發現網路服務。ebXML 和 RosettaNet:網路服務的替代技術。網路服務安全規範。總結。
**3. 分散式訊息層安全的基礎。**
- 網路服務的信息安全挑戰。共享金鑰技術。公鑰技術。總結。
**4. 保護 XML 訊息的身份和完整性。**
- XML 簽名的介紹和動機。XML 簽名基礎。XML 簽名結構。XML 簽名處理。XML 簽名元素。XML 簽名的安全策略。總結。
**5. 確保 XML 訊息的機密性。**
- XML 加密的介紹和動機。XML 加密基礎。XML 加密結構。XML 加密處理。結合使用 XML 加密和 XML 簽名。總結。
**6. 可攜式身份、認證和授權。**
- SAML 的介紹和動機。SAML 的運作方式。將 SAML 與 WS-Security 結合使用。應用 SAML:自由計畫。總結。
**7. 在 SOAP 中建立安全性。**
- WS-Security 的介紹和動機。用安全性擴展 SOAP。WS-Security 中的安全令牌。提供機密性:WS-Security 中的 XML 加密。提供完整性:WS-Security 中的 XML 簽名。訊息時間戳。總結。
**8. 傳達安全政策。**
- WS-Policy。WS-Policy 框架。WS-SecurityPolicy。總結。
**9. 網路服務的信任、存取控制和權限。**
- WS-* 安全規範系列。XML 金鑰管理規範 (XKMS)。可擴展存取控制標記語言 (XACML) 規範。可擴展權限標記語言 (XrML) 管理規範。總結。
**10. 使用 BEA 的 WebLogic Workshop 建立安全的網路服務。**
- 安全層逐步說明。WebLogic Workshop 網路服務逐步說明。總結。
**附錄 A. 安全性、密碼學和協議背景資料。**
- SSL 協議。質數測試。RSA 密碼學。DSA 數位簽名演算法。區塊密碼處理。DES 加密演算法。AES 加密演算法。雜湊細節和要求。SHA1。Silvio Micali 的快速驗證/撤銷。數位簽名清單的消息標準化。Base-64 編碼。PGP。
**詞彙表。**
**索引。**