November 06, 2003

IBM gets ready for SOAs

IBM supports Web services security

IBM on Thursday  is announcing its support of key industry standards for Web services security for its WebSphere and Tivoli server applications that will better enable those products to fully embrace service oriented architectures (SOAs).

Big Blue is betting big on SOAs being widely adopted over the next few years as corporate users search for ways to efficiently and cost-effectively tie existing heterogeneous hardware and software platforms together. Thursday's announcements are another step following several others earlier this year designed to help users get ready to move to the new architecture.

"What is driving in interest in (SOAs) are the incredibly heterogeneous environments users have to support. Either through mergers and acquisitions or new software they themselves produce, they will have a patchwork of hardware and software they use to get their most important work done. And the best way to get efficiencies out of such an environment is to make it look more homogenous," said Bob Sutor, director of IBM's WebSphere software in Somers, N.Y.

Typically within an SOA environment, business processes can be exchanged as interchangeable tasks or including Web services, Java adopters, and older application programming interfaces (APIs) like Corba. This would allow a bank, for instance, to use the same computing services infrastructure to take care of account transfer requests coming from tellers, ATMs or a Web-based application. This can help eliminate the need for multiple applications that can be expensive to maintain, IBM executives said.

To help this effort along, IBM executives said they will support the WS-Security roadmap and standards for expressing identity information including the Security Assertion Markup Language (SAML) and Kerberos. SAML enables authentication, authorization and identity information that can be exchanged among companies and their trading partners. IBM will also support Kerberos, a popular Windows network authentication protocol that enables users to sign onto a Windows desktop system and automatically access a range of applications using just their Web browser.

IBM plans to add native support for Kerberos within WebSphere, a company spokesman said.

"These announcements are aimed to tie together the picture of Tivoli and WebSphere being linked arm and arm as we advance the underlying security management. We want to show what you can do through middleware and security policies, and then how you build these applications on the Websphere platform," Sutor said.

Corporate IT shops will be able to use IBM's federated identity software to create a single, uniform way to set parameters for allowing access to Web applications, or packaged software including CRM and ERP applications, and legacy systems running high-volume transactions, such as CICS.

IBM plans to deliver by year's end a new version of WebSphere that will debut security enhancements through an upcoming version of Tivoli Access Manager (V5.1). These improvements will provide Web single sign-on capabilities to access portals, applications and back-end systems, a company spokesman said.

IBM also said it will build in features to its upcoming WebSphere Business Integration and WebSphere MQ products that will enable IBM mainframes to improve their network performance by defining security policies for a select group of Web or legacy applications. This capability will be available by year's end.

IBM officials also announced they will expand WebSphere's Web services support for software protecting sensitive personal financial data in outsourced Web-based Java applications including 401Ks and Human resources applications.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.