Nova Patents
EP1599017A1

Securing web services

Abstract

A scalable policy-based Web Services security architecture that incorporates a combination of authentication with service discovery, evaluation of access policies, and capturing the result of this process in a signed, security token, thus, allowing efficient processing for each service request in a secure manner. A method for securing a Web Service comprises discovering the Web Service in response to a service request and determining an access policy for the Web Service separately from the actual service based on the service request.

EP1599017A1, drawing sheet 1
Sheet 1 of 6

Term

Term ended

Projected expiry passed 29 April 2025, 1.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

10 claims: 6 independent, 4 dependent

  1. 1
    A method for securing a Web Service, the method comprising:discovering the Web Service in response to a service request;and determining an access policy for the Web Service separately from the actual service based on the service request.
  2. 2
    A method for securing a Web Service, the method comprising:sending one or more invocations to the Web Service after discovering the Web Service.
  3. 5
    A computer readable medium comprising programming instructions for a web server coupled to a network for serving service requests, the web server linked to a plurality of clients, the programming instructions comprising:discovering the Web Service in response to a service request;and determining an access policy for the Web Service separately from the actual service based on the service request.
  4. 6
    A web server for serving Web Services to a plurality of clients linked via a network therewith, the web server comprising:an interface coupled to a cache for storing identity and access policy information;an access controller including a policy engine to evaluate access policies and encode its decision in a security token;and a module for securing a Web Service based on an access policy determined for the Web Service separately from the actual service based on a service request.
  5. 9
    A system for securing a Web Service, the system comprising:a client that sends a service request for a Web Service over a network;and a web server coupled to said network to serve the Web Service across different administrative domains based on a pre-computed policy.
  6. 10
    A method on a server linked to a network of a plurality of clients, the method comprising:receiving a service request from a client;using a first access controller element to discover a service in response to the service request;and using a second access controller element which separates access control enforcement from the actual service based on the service request.