| By Mark O'Neill | Article Rating: |
|
| September 8, 2009 01:00 PM EDT | Reads: |
310 |
Joe McKendrick kicks off a thread on the current state of SOA Security. As usual, most discussion of SOA Security applies to "how SOA can be made secure". This is understandable. And, as some commentators have pointed out, there is a body of Best Practice out there on how to secure services in an SOA. For example, Randy Heffner provides lots of good advice on how to secure the services in an SOA)
But, there has been relatively little debate on the flipside of SOA Security - how SOA can apply to security.
Because, really, "SOA Security" is two separate things, solving two separate problems. The first, most obvious thing, is that it applies security to SOA. The problem it is solving here is "SOA is insecure". Randy Heffner's advice is good here: there are products and procedures for applying security to SOA. But, "SOA Security" also has the meaning of "applying SOA principles to security". i.e. "SOA-flavored security", if you like. The problem which is being solved there is the difficulty of deploying security. Joe McKendrick hints at this in his comment here
: "Could security services be delivered through the SOA infrastructure, and provide an enterprise-level solution, versus application or system-level approaches?"
"SOA-flavored Security" means making security more manageable and easy to deploy by isolating re-usable components of security and providing them as managed services. For example, the OASIS DSS standard explains how digital signature services can be used in order to provide signing and signature validation services over the network, accessed using a Web Services interface. This solves a knotty problem, and provides a good framework for key management. Similarly, specifications such as XKMS, XACML, and WS-Trust are really all about applying SOA to security, to solve interoperability problems, not about "making SOA secure".
I think that too many SOA Security articles focus only on the first meaning of SOA Security (making SOA more secure) than on the second (applying SOA principles to security to make it more easy to deploy and manage).
Read the original blog entry...
Published September 8, 2009 Reads 310
Copyright © 2009 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Mark O'Neill
Mark O'Neill is CTO at Vordel, the XML network management company. He is also author of the book "Web Services Security" and contributing author to "Hardening Network Security" from McGraw-Hill/Osborne Media. Mark is responsible for overseeing Vordel's product development roadmap and also advises Global 2000 firms and governments worldwide on their tactical and strategic adoption of XML, Web Services and SOA technologies. He holds a degree in mathematics and psychology from Trinity College and graduate qualifications in neural network programming from Oxford University.
- AJAX World RIA Conference & Expo Kicks Off in New York City
- "Government IT Expo" to Highlight Cloud Computing and SOA
- Cloud Computing CEOs & CTOs to Speak at 4th International Cloud Expo
- Ted Weissman and Lois Paul & Partners PR Firm
- Vizioncore Named Bronze Sponsor of 4th Virtualization Conference & Expo
- Publishing Synergy: Blog, Twitter and Ulitzer
- SOA, BPM, CEP: Getting IT Budget in a Tight Economy
- SOA World Magazine’s 8th Annual "Readers' Choice Awards" Nominations Open
- The Network-Centric Computing Model
- Orchestration in the Cloud to Manage Lower Operational Costs
- AJAX World RIA Conference & Expo Kicks Off in New York City
- "Government IT Expo" to Highlight Cloud Computing and SOA
- Cloud Computing CEOs & CTOs to Speak at 4th International Cloud Expo
- Ted Weissman and Lois Paul & Partners PR Firm
- Improving the Efficiency of SOA-Based Applications
- Vizioncore Named Bronze Sponsor of 4th Virtualization Conference & Expo
- Make Your Design Ideas Speak: Using UML in PowerBuilder Projects
- Publishing Synergy: Blog, Twitter and Ulitzer
- SOA, BPM, CEP: Getting IT Budget in a Tight Economy
- SOA World Magazine’s 8th Annual "Readers' Choice Awards" Nominations Open
- AJAX World RIA Conference & Expo Kicks Off in New York City
- JSON vs XML - A Jason vs Freddie Sequel
- Processing XML with C# and .NET
- BPEL Processes and Human Workflow
- Open Source Database Special Feature: An Introduction to Berkeley DB XML
- "HP's Problem Ain't the SAP Install," Says Sun's Schwartz
- eXist - An Introduction To Open Source Native XML Database
- Digitizing the Planet: Google Earth vs MSN Virtual Earth vs MapQuest
- Generating XML from Relational Database Tables
- Product Review: Altova Enterprise Suite 2005



























