Ignore standards for web services security

Analysts tell firms to take proprietary route to secure web services-based transactions

Lisa Kelly

Companies should take the proprietary route to provide security for web services-based transactions over the next three years, according to analysts.

In a research paper, Security Pattern Standards Face a Long Road to Maturity, analyst Gartner advises firms to rely on vendor-provided technology to provide security for web services-based transactions until 2006, even though it may not comply with standards.

Advertisement

Although there are no products as such, major vendors sell application development packages, such as Microsoft's Visual Studio .Net, which have the facility to build security into web services.

The Gartner report argues that web services security is immature and that complex, multi-party web services will require newer, more versatile security patterns for electronic transactions.

By using XML, Simple Object Access Protocol and Web Services Description Language, WS-Security related specifications are designed to be used together to provide a rich, secure web services environment.

But Gartner warns that the key security specification, WS-Security, which protects the confidentiality of a message and is backed by the Organisation for the Advancement of Structured Information Standards, will not provide a complete security solution for complex web services, where transactions cross organisational boundaries.

"WS-Security establishes a model that brings together formerly incompatible security technologies, such as public key infrastructure, XML Digital Signature and XML Encryption," said the report's author, Jess Thompson.

"Although WS-Security is the security cornerstone, it is only the beginning and must be extended with additional specifications that deal with policy, trust and privacy issues."

Mike Thompson, principal research analyst for the Butler Group, agreed with the Gartner view, but said standards will take 18 months, rather than three years, to mature.

He told vnunet.com that "in the first flush of enthusiasm" Butler had told firms not to take the proprietary route. But with security standards not expected to be agreed within the next 18 months, the analyst firm's view had changed.

"Now we are advising to go for the vendor approach as companies can't wait that long, but to get assurances that there will be some interoperability with open standards," he said.

Marc Chanliau, director of XML technologies at security firm Netegrity, said: "Why rely on vendor-provided technology that may not comply with standards to provide security if there are enough standards widely embraced by the industry?"

But Gartner's Thompson countered: "Although there are standards to secure the message, there are no mature standards for the security of the interfaces when different components talk to each other."

Gartner advises businesses to investigate the use of WS specifications when they are embarking on a strategic direction, to expose functionality to a large number of business partners as web services.

Also, if they are implementing complex, multi-party web services, they must have the IT expertise to implement the appropriate security, and work with trading partners capable of using the same security technologies.

To implement security today, Gartner recommends that companies implement simple point-to-point web services that can be secured using mature technologies like secure sockets layer and digital certificates.

It added that they should expose those web services to only a small number trading partners and consider making large groups of transactions using proven, secure batch technologies.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

ROI holds back web services

But a high proportion of UK firms have started nonetheless

E-tailers prepare for Xmas bonanza

Load testing tools allow sites to be pushed to the limit

Related whitepapers

Related jobs

Most watched

Summit: Views From the Valley

V3.co.uk's US office weighs in on the information overload crisis

John Chambers speaks on collaboration

Cisco boss talks up new offerings

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

deloitte

Summit interview: Deloitte discusses security implications of the data deluge

We chat to Mike Maddison, UK head of Security, Privacy...

ibm logo

IBM boosts mobile shopping with WebSphere Commerce

Update designed to give mobile users a richer, more personalised...

Summit: Intel discusses processors for data overload (part 2 of 2)

More thoughts on how servers can help manage overload

chrome logo

Google plans a Mac version of Chrome

A Mac-friendly version of the browser is in the pipeline

Primary Navigation