S2ML: a security standard for e-business

2001-12-29 12:52:49【作者】 畅享网 【进入论坛】
本文关键字 理论探讨 协同商务
广告

S2ML: a security standard for e-business


The aim of S2ML is to provide a standard for secure e-commerce transactions using XML

As e-business expands from companies focusing on their own products and services and dealing with consumers to more business-to-business dealings, the need for increased security becomes apparent. Most security models are designed for a single enterprise, which makes it difficult for collaborating companies to ensure transactions are secure across companies.

A new open security standard called Security Services Markup Language (S2ML) is being developed to address this interoperability problem. A group of leading technology companies, including Oracle?, Netegrity?, Verisign?, Sun? Microsystems, and PricewaterhouseCoopers have worked on S2ML. Their aim was to create the first standard for enabling secure e-commerce transactions using extensible markup language (XML).

XML

S2ML consists of two XML schemas, name assertion and entitlement, as well as an XML-based request/response protocol for authentication and authorization.

    Name assertions
    In the S2ML model, when a customer, partner, or supplier is authenticated, a name assertion is created. Such assertions describe the type of authentication, who the authenticator is, and who is being authenticated.

    Entitlements
    Information on authentication, authorization, and profile is carried in collections of data called entitlements. An issuing authority inserts these entitlements.

Benefits

The proposed standard has various features to facilitate the smooth flow of business across web sites.

    Interoperability
    When service providers and companies of any size use S2ML for e-businesses, they can exchange authentication and authorization information securely even when partners have different security platforms.

    Open solution
    A number of XML document exchange protocols and frameworks can be used with S2ML, including SOAP, OAG, MIME, Biztalk, and ebXML.

    Single sign-on
    Partnered companies using S2ML enable their users to travel across sites keeping their entitlements, without having to sign-on at every stop.

B2B and B2C environments

The S2ML standard offers features for business-to-business (B2B) as well as business-to-consumer (B2C) transactions.

For B2B, with its business transactions across multiple web sites, there's the "portability" of security in XML documents. Basically, S2ML provides standard security tags for XML documents, which can be based on any agreed upon vocabulary for secure B2B transactions.


S2ML will give companies a new common language for describing security information and sharing it with multiple business partners

Users of B2C sites often want to quickly jump to related sites and information without having to log on each time. S2ML's method of allowing users' security information to "travel" with them across multiple sites fills the need for single sign-on and access control.

While it isn't a new authentication or authorization solution, S2ML will give companies a new common language for describing security information and sharing it with multiple business partners. With the continuing growth of e-business and the increasing frequency of online collaborations, the creation of such a security standard is vital. The S2ML specification must now go to the World Wide Web Consortium (W3C?) and the Organization for the Advancement of Structured Information Standards (OASIS) for consideration.

For more information on the proposed standard, go to the S2ML site.

如果您希望与本文章的作者或其所在机构,进一步交流,请联系:畅享网 姜小姐
jill.jiang@amt.com.cn | 021-51096826-112 | 在线联系
蓝凌知味堂知识地图在项目型组织中的应用

将项目实施标准化,项目内容知识化,从而降低企业人力资源成本、提高工作效率、提升管理水平,增强企业的核心竞争力。

云顶山涧——吴勇毅SaaS不是自来水,CIO如何面对尴..

面对SaaS在中小企业的推广的障碍与瓶颈,CIO要如何正确分析企业的IT需求,怎么样才能对症下药、有效选型与实施。

夏敬华的KM专栏如何评估业务领域的知识管理实..

KM准备度模型如同温度计,使得我们能够很清楚地测量出组织的“体温”,为发现企业在知识管理方面存在的问题提供依据。

机遇与挑战并存 协同软件大比拼

2007年,中国协同软件市场份额达到了16.21 亿元人民币,较2006年13亿增长了24.7%。2008年的协同软件,呈现出鲜明的“进、转、合”并举的态势。协……