Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

IBM moves on secure mashups

Big Blue promotes interoperability with donation of SMash technology to OpenAjax Alliance


IBM is unveiling technology to secure mashups Thursday and is donating it to the OpenAjax Alliance, an organization promoting AJAX (Asynchronous JavaScript and XML) interoperability.

Through IBM's SMash (secure mashup) technology, information from different sources can communicate with each other, but the sources are kept separate to prevent the spread of malicious code. SMash keeps code and data from each of the sources separated while allowing controlled sharing of data through a secure communication channel.

Mashups are defined by IBM as Web applications that pull information from multiple sources such as Web sites, enterprise databases, and e-mail to present a single view. But mashups have been beset by security risks, IBM said.

"What we were striving for was to have [mashups] interact with other information on a page in a secure manner," said David Boloker, CTO of emerging Internet technologies in the IBM software group.

SMash prevents information from one domain trying to access information on the page, Boloker said. But developers can allow access if they choose.

"[It] allows you to communicate with other parts of your Web page in a secure manner," he said.

"You're preventing JavaScript coming from another site taking over control of the Web page and not only taking control of the Web page, they could be trying to deliver erroneous information, could be trying to erase files on your hard drive, anything like that," said Boloker.

The technology is being donated to the OpenAjax Alliance and is to become part of OpenAjax Hub 1.1, which goes to general release in June, Boloker said. Once available, SMash can be used in Web pages in mashups.

"I think SMash could potentially address a need in the AJAX market – namely enabling safer client-side cross-domain access to multiple sites," said analyst Jeffrey Hammond, senior analyst for application development at Forrester Research. "This client-side cross-domain access pattern is becoming increasingly popular when developers want to mix in technology from multiple sites, but don’t feel comfortable importing that code into their server domains."

Building on top of OpenAjax Hub is a strength of SMash, Hammond said.

Paul Krill is editor at large at InfoWorld.

Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





Are you ready for event-driven business?
"Faster than a speeding bullet" doesn't just refer to superheroes anymore, it's the velocity your business needs to compete. In this webcast you will learn strategies you can implement today that will keep your systems ahead of the increased business velocity. Sponsor: Progress Sonic

»  Click here to view this Webcast
  The Silver Lining: Cloud Computing
This IT Strategy Guide digs deep into cloud computing helping put you ahead of the curve on this hot topic. It explores the differences between cloud computing, grid computing and utility computing and then helps you see where and how each applies to your business. Sponsored by Box.net

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist