III. WEB SERVICES SECURITY
E-commerce relies on information exchange between
trading partners over networks, often the Internet. Managing
security is reasonably important and necessary.
A. Security Requirements
There are always security risks since messages could be
stolen, lost, or modified. It is thus crucial that the use of Web
services, stand-alone or composed, provide strong security
guarantees. As a result, four security requirements must be
addressed to ensure the safety of information exchange among
trading partners:
1. Confidentiality guarantees that the exchanged information
is protected against eavesdroppers.
2. Authentication guarantees that access to e-business
applications and data is restricted to only those who can
supported by“the Fundamental Research Funds for the Central
Universities”
978-1-4244-7161-4/10/$26.00 ©2010 IEEE
provide the appropriate proof of identity.
3. Integrity refers to assurance that the message was not
modified accidentally or deliberately in transit.
4. Non-repudiation guarantees that the sender of the message
cannot deny having sent it.
5. Authorization is the process to decide whether or not the
entity can access the particular resource.