Newletter Sign Up
Posts on the
Design Decomposition Blog
Iridium Satellite Collision in Space
You might have seen the recent news reports about the collision between U.S. and Russian communication satellites. The U.S. satellite was one of the Iridium satellites. What wasn’t reported and you probably don’t know is that an object database management system (ODBMS) is an important part of the Iridium system. Even though ODBMSs are a [...]
February 13, 2009
(The Acronym) SOA is (Perhaps) Dead (at Some Companies); Long Live Services
I am now also posting on the Cutter Blog. My initial posting is (The Acronym) SOA is (Perhaps) Dead (at Some Companies); Long Live Services. It is a response to Anne Thomas Manes’ SOA is Dead; Long Live Services on her blog at the Burton Group.
January 9, 2009
Atomicity
The typical definition of an atomic task or process is one that cannot be decomposed further. This is vague and subject to interpretation. The Decomposition Matrix on this site uses a specific definition: A task (for business process diagrams) or a process (for data flow diagrams) is atomic if every input relates to every output [...]
December 3, 2008
Well-Formed Business Process Diagrams
My last posting referenced the criteria for a well-formed business process diagram mentioned in Business Process Driven SOA using BPMN and BPEL by Matjaz B. Juric and Kapil Pant. I am going to expand on their criteria to create a more comprehensive definition of a well-formed business process diagram. To start, here are three criteria [...]
November 18, 2008
Recent Business Process Modeling Books
I recently received two new books on business process modeling. Both books looked interesting because they had great titles. As it turns out, one book is great and the other not so good. The not so good book is Business Process Driven SOA using BPMN and BPEL by Matjaz B. Juric and Kapil Pant. There [...]
October 9, 2008
The Design Decomposition Blog
is written by Doug Barry.

Security and authorization is a hot topic with Web Services. In fact, security and authorization specifications are currently in flux. This is often the reason cited for not proceeding with any work related to Web Services. Nevertheless, the fact that these specifications are in flux should not hold you back from experimenting with Web Services.

Much can be done without having the specifications complete. Nearly all organizations should be able to find some areas to experiment with Web Services that have low requirements for security and authorization. In fact, Chapter 7 of Web Services and Service-Oriented Architectures: The Savvy Manager's Guide discusses the stages of adoption for Web Services. The first four of the five stages do not require much security and authorization because they involve internal systems.

Security and authorization specifications described on this site are listed below. You can also navigate among the specifications by using the menu tree at the bottom of each page.

Specialized XML firewalls offer the promise of protecting internal systems when using Web Services. Traditional firewalls offer protection at the packet level and do not examine the contents of messages. XML firewalls, on the other hand, examine the contents of messages. This includes the SOAP headers and the XML content. They are designed to permit authorized content to pass through the firewall. For a listing of XML firewall products, click here.

Related content for: Security and authorization

More on the general topic: Web Services specifications

Read more free articles on this site

There are nearly 400 pages of articles on this site with over 130 pages on Web services and service-oriented architecture.

Search this site for more articles

Custom Search

Browse this site for more articles

Click on the topics below to browse the articles on this site. You can see more detail by clicking on the arrows. This highlights the location of the current article: Security and authorization.

Loading...

Related recent articles from Google News

SOA Software Announces Ready-to-Use SOA Governance for Microsoft
MarketWatch (press release)
With the goal of helping customers govern a wide range of Microsoft Service-Oriented Architecture (SOA) use cases, SOA Software has loaded this product with prebuilt, pretested, and governance-ready WCF services, clients, tools, policy, ...
and more »
8 Feb 2012 at 6:03am
A better approach to biometrics
FCW.com
Although the government has yet to take full advantage of it, the process of developing those biometric solutions has evolved internationally and commercially to apply a vendor-independent, scalable and repeatable service-oriented architecture (SOA) ...

7 Feb 2012 at 10:10am
NASA wants to put Web services in agile-like cloud
GCN.com
The Web infrastructure will service internal and public-facing applications and sites, using an interoperable, standards-based and secure environment, the document states. Currently, each NASA center and its affiliated satellite facilities has its own ...

7 Feb 2012 at 9:26am
Red Hat Introduces Virtual Storage Appliance for Amazon Web Services
MarketWatch (press release)
Red Hat provides high-quality, affordable technology with its operating system platform, Red Hat Enterprise Linux, together with cloud, virtualization, management, storage and service-oriented architecture (SOA) solutions, including Red Hat Enterprise ...
and more »
7 Feb 2012 at 7:06am
CDYNE Corporation Launches International Address Verification
Sacramento Bee
7, 2012 -- /PRNewswire/ -- CDYNE Corporation, a leading provider of Communication and Data Quality Web Services, announced today the launch of PAV-I, an international postal address verification API (Application Programming Interface) which validates ...
and more »
7 Feb 2012 at 8:43pm
More related news on: Security SOA OR "service-oriented architecture" OR "Web services"