Uma Arquitetura de Segurança para Mecanismos de Controle de Acesso Baseados em Serviços Web

Ricardo T. MacedoBruno A. MozzaquatroLuiz D. Biazus NetoRaul C. Nunes

In examining efforts to improve the mechanisms for access control, there is the adoption of Web services technology to ensure interoperability across heterogeneous technology domains. However, there are reported concerns about the confidentiality of requests and authorizations that pass through the channel of communication. This paper proposes a security architecture that determines how messages should be formed, transported and processed in order to inhibit attacks on the confidentiality of information managed. It presents a proof of concept with the development of a prototype based on WS-Security, WS-BPEL and WS-Policy, environmental testing and feasibility of use.

