The objective of the paper is to enlighten the applicability of component technology in deploying security models to protect Web transactions. The proposed component-based security model is a substitutive methodology for conventional methods that are vendor dependent. The model prefers the Extensible Markup Language (XML) format to represent Web transactions, because of the multi-platform nature of modern Web applications. A granular approach is adopted in signing and encrypting the XML document. The paper also describes a distinct method used for key distribution. In addition, access control measures are also recommended in the model to protect data resources at the server against unauthorized access.
Published in:
Local Computer Networks, 2002. Proceedings. LCN 2002. 27th Annual IEEE Conference on
Date of Conference: 6-8 Nov. 2002