分析了目前身份认证系统中存在的问题,以及SOAP技术在分布式系统集成和交互上的优势,并在此基础上提出了基于SOAP的强身份认证系统。利用该身份认证系统,能够更加有效地解决网络应用系统中通信双方的身份认证问题,从而建立起真正的双向身份认证,并且对于防范当前流行的网络重放攻击更加安全有效。通过XML实例文档测试表明,该设计方案为解决系统安全性、兼容性提供了一种实用方法。
SOAP is a protocol for the exchange of information in a distributed environment and it is a XML-based protocol.This paper analyzes the problems existing in the current identity authorization system.Based on the integration and exchange advantages of SOAP applied to the distributed system,it puts forward an identity authorization based on SOAP approach.By establishing a complete mutual identity authorization,this approach can effectively solve the identity problem in the process of communication under the network application system.It is also more secure and effective in preventing the network replay attack.Test of the XML document shows that this case provides a practical method for the security and compatibility of the system.