web服务的广泛应用和网络技术多元化的发展迫切需求一个既能实现web服务安全,又能兼容各种客户端的安全框架。在Axis2的基础上,设计并实现了一个完整的、符合WS-Security规范的web服务框架。框架以文件配置、消息加密和程序控制实现web服务安全,采用SOAP通信协议解决了与各种客户端通信的问题。测试结果表明,此框架可以实现数字签名、消息加密和基于角色的访问控制,能够接收各种基于SOAP协议的客户端请求,具有很好的安全性和兼容性,为企业的web服务安全提供了一个有效的解决方案。
With the extensive application of web services and the rapid development of network technology,a web service security framework,which is compatible to various clients,is in need.We use the file configuration,encryption algorithm and program control module,implement a web service security framework which satisfies WS-Security specification based on Axis2.The service communicates with various clients under SOAP protocol.The experimental results indicate that the framework implements digital signature,message encryption,roles based access control and could communicate with various web services clients that are based on SOAP network communication protocol,has a good security and compatibility.The security framework is an efficient solution for web service of enterprise.