Turkish Journal of Electrical Engineering and Computer Sciences
DOI
10.3906/elk-1303-12
Abstract
Web service-based application has become one of the dominative ones of the Internet. This trend brings more and more security challenges in reliability, confidentiality, and data nonrepudiation, especially in some systems that have massive diversified resources. An improved framework for secure accesses of Web resources is presented and implemented by extending and enhancing the Spring Security framework. It improves the security level of systems for identity authentication, authorized access, and secure transmission. The highly safe authentication is based on the integration of an improved authentication module of Spring Security with a U-key method and a RSA algorithm. For authorized access, the Spring Security's ACL (access control list) mechanism is improved by optimizing the domain object-level access control. For secure transmission, a compromising method is presented to take both the security level and the speed of data transmission into account by means of mixing the RSA and DES algorithms. In addition, the security interceptor of Spring Security is extended and a series of security filters are added to keep Web attacks away. The above improved security framework has been applied to an online virtual experiment platform named VeePalms. The experimental results show that most security problems with high severity in the system have been solved and medium-low severe problems decreased dramatically. Moreover, VeePalms has been used in practice for about 2 years, which has proved the effectiveness of the security framework.
Keywords
Web service, Spring Security, authentication, authorized access, secure transmission
First Page
774
Last Page
792
Recommended Citation
JIANG, WENBIN; XU, HUI; DONG, HAO; JIN, HAI; and LIAO, XIAOFEI
(2016)
"An improved security framework for Web service-based resources,"
Turkish Journal of Electrical Engineering and Computer Sciences: Vol. 24:
No.
3, Article 6.
https://doi.org/10.3906/elk-1303-12
Available at:
https://journals.tubitak.gov.tr/elektrik/vol24/iss3/6
Included in
Computer Engineering Commons, Computer Sciences Commons, Electrical and Computer Engineering Commons