Nova Patents
EP1599017B1

Securing web services

Abstract

This record has no abstract on file.

EP1599017B1, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Expired 29 April 2025, 1.4 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

9 claims: 3 independent, 6 dependent

  1. 1
    A method for securing a Web Service (390) provided by a Web server (115) for a client (105), the method comprising:discovering (200) the Web Service (390) in response to an initial service request from the client for the Web Service (390);and determining (205) an access policy (125) for the Web Service (390) separately from the actual service based on a subsequent service request from the client (105) for invocation of the Web service (390).
  2. 2
    A method, as set forth in Claim 1, wherein determining the access policy for the Web Service (390) separately from the actual service based on the service request further comprises÷ using a pre-computed policy.
  3. 3
    A method, as set forth in Claim 2, wherein using a pre-computed policy further comprises:evaluating access policies (125) for the Web Service (390) to determine identity and access policy information;and encoding the identity and access policy information in a security token (410) based on said pre-computed policy.
  4. 4
    A method, as set forth in Claim 1, the method comprising:serving the Web Service (390) across different administrative domains based on a pre-computed policy.
  5. 5
    A method, as set forth in Claim 1, the method comprising:using (505) a first access controller element (375) to discover the Web Service (390);and using (530) a second access controller element (385) which separates access control enforcement from the actual service based on the service request.
  6. 6
    A computer readable medium comprising programming instructions for a web server (115), the programming instructions, when executed, performing a method comprising:discovering (200) a Web Service (390) on the Web server (115) in response to a service request from a client;and determining an access policy (125) for the Web Service (390) separately from the actual service based on a subsequent service request from the client (105) for invocation of the Web service (390).
  7. 7
    A web server (115) for serving Web Services (390) to a plurality of clients (105), the web server comprising:an interface (395) coupled to a cache (397) for storing identity and access policy (125) information;an access controller (375) including a policy engine (380) to evaluate access policies (125) and encode its decision in a security token;and (125) a module (120) for securing a Web Service (390) based on an access policy (125) determined for the Web Service (390) separately from the actual service based on a subsequent service request from the client (105) for invocation of the Web Service (390).
  8. 8
    A web server according to Claim 7, wherein the access controller (375) discovers the Web Service (390) in response to the service request.
  9. 9
    A web server according to Claim 7, wherein the module sends one or more invocations (440, 425) to the.Web Service (390) after discovering the Web Service (390).