July 08, 2003

Microsoft, IBM advance Web services spec

Security is focus of proposal

Building on their previous efforts to create a framework for producing secure and interoperable Web services, IBM, Microsoft, and several other leading software companies on Tuesday will announce a specification intended to help corporate users simplify identity management.

The proposed WS-Federation specification features a set of Web services technologies intended to give developers a standard way of adding security capabilities to any Web service they build. The specification defines mechanisms that allow developers to manage and establish trust relationships across companies and domains using a variety of different types of security solutions, including support for federated identities, according to company officials.

"This will let companies tie their identity systems to each other in a way that lets them trade information back and forth about users and systems and then federate that data across the Internet no matter what security infrastructure they are using," said Steven VanRoekel, Microsoft's director of Web services, in Redmond, Wash.

By allowing corporate users with a variety of security solutions to interoperate, administrators can afford to authenticate a single employee just once, allowing that employee to work with Web services available from his or her company as well as those of the company's business partners.

"What this will do is provide a way for trust relationships to be established," said Carla Norsworthy, director of dynamic e-business technologies at IBM in Somers, N.Y.

"Users can carry out federate identity and not inconvenience users with remembering lots of passwords, [and] administrators can now do this on policy-based systems,'' Norsworthy said.

In April of last year IBM and Microsoft laid out a road map called "Security in a Web services World," which laid out the framework of specifications for WS-Federation. The WS-Federation specification builds on the foundation WS-Security, which includes WS-Policy, WS-Trust, and WS-SecureConversation. Working together, these specifications are intended to enable a complete model of security functions for Web services.

In a related announcement, Microsoft and IBM also are delivering a white paper entitled, "Federation of Identities in a Web Services World."  The white paper outlines the challenges associated with federated identity management as well as describes a Web services model that allows companies to issue and rely on information from other companies and domains. This new model also allows them to broker trust and attributes across domains in a more secure manner so as to maintain individual and business privacy, officials from the companies said.

IBM and Microsoft officials will be accepting feedback on the specification from across the breadth of the development community and expect to present the completed specification before industry groups deliberating on Web services such as the Web Services Interoperability (WS-I) and others "in the next several months."

During a keynote at the Burton Group's Catalyst conference in San Francisco on Tuesday, IBM will demonstrate early implementations of interoperability across IBM and Microsoft systems using WS-Federation. Norsworthy said IBM expects to deliver products based on the specification "towards the end of this year."

"I see this as the linchpin spec that explains how all the other pieces fit together. However, we still have specifications on privacy and authorization left to complete, but this one really pulls the whole picture together," Norsworthy said.

Microsoft will also show off early versions of the specification at this week's conference and will also deliver initial products that take advantage of the completed specification by the end of 2003, according to VanRoekel.

Close

On Twitter now

Architecture

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Architecture Resource Alerts

Subscribe to the Today's Headlines: First Look Newsletter

Find out what will be news for the day, with our first-thing-in-the-morning briefing.

©1994-2009 Infoworld, Inc.