透過您的圖書館登入
IP:3.142.96.146
  • 學位論文

Web Services應用在企業資訊整合的安全性議題及解決方案之研究

The Security Issues and Solutions of Web Services Applied to Business Information Integration

指導教授 : 陳文賢

摘要


本篇論文對企業資訊整合的應用提出一個完整的解決架構並分析其可能的安全問題。目的是為提供建造Web Services系統一個安全性的參考的方向,並由完整的模型探討來發現其中可能的安全議題,在設計安全系統時就能注意而盡量避免。 本論文一開始先分析Web Services可應用在哪些企業資訊整合的模式上,再由這些模式的流程找出最能代表討論安全問題的流程模型。接著依此模型探討各種可能的安全解法,最後分析所提的安全解法有無安全漏洞。 經本論文研究後,可得以下結論: 本篇論文整理出一個Web Services安全性的完整架構,任何有關安全的解決方法都可放在此架構中討論,分析其能放在此架構的哪一部份、和其他部分如何連結、其所能達到的安全防禦效果如何。 現有的安全技術其實都可對其做探討看看如何用在Web Services上,例如隱私問題或建立信任問題已在傳統網路問題中有不少的探討,而這些問題在Web Services中探討的卻還很少,這些對傳統網路的既有研究要如何套用在Web Services上,是可以多加研究的。 Web Services建立在目前的資訊系統上,所以也繼承了所有目前可能會發生的安全性問題,還會再加上因為Web Services的特性而產生的安全問題。 企業要用Web Services在內部做資訊整合的安全風險較能控制,但若和企業外部做整合安全風險就會很多風險要素需要考量。 要使用Web Services在企業資訊整合方面達到足夠的安全還有許多工作需完成,如:防火牆的設計、SOAP Server的安全性考量、內部處理資料的Filter、防毒軟體、認證的管理、以往未解決的安全問題如何解決,企業實行Web Services的安全風險如何評估。

並列摘要


This Paper suggests a high level total solution for the security problems of the application to business integration and we discuss the essential security problems of this structure. This solution provides a security guide and analysis base for the implementation of the Web Services. We analyze what business integrate application can be implemented by web services. We suggest a model that can represent all the security process of these applications. Then we suggest possible security solutions about this model and analysis possible security holes of this solution. Our including as follows: We suggest an entire structure of web services security. Every existed security solution can use this model to analyze if they can use for web services security、where should they be combined with the system、how they are connected with other security solutions, and how to evaluate their efficiencies. Web Services inherent the traditional security problem because it build bases on the current information systems. More addition, it produces more problems because of the characters of Web Services. We have better control when we use Web Services technology for inner integration of business than outer integration. We still have a lot of works to do for Web Services securely applied to business integration. For instance:the design of a firewall、how to make a secure SOAP server、Filter of inner data、anti-virus software、hoe to solve the existed unsolved security problem、and how to evaluate the risk of the implementation of business integration by Web Services.

並列關鍵字

ERP policy Integration Broker trust Web Services EAI privacy B2B Integration security

參考文獻


[2] Gunjan Samtani and Dimple Sadhwani. EAI and Web Services. Web Services Business Strategies and Architectures,October 2001.
[3] Gunjan Samtani and Dimple Sadhwani. B2Bi and Web Services. Web Services Business Strategies and Architectures, January 2002.
[5] Piers Wilson. Web Services Security. Network Security Volume: 2003, Issue: 5. May, 2003, pp. 14-16.
[6] Elspeth Wales. Web Services Security. Computer Fraud & Security Volume: 2003, Issue: 3, March, 2003, pp. 15-17.
[7] Kani Anshankar. Enterprise Resource Planning and Web Services. Web Services Business Strategies and Architectures, April 2002.

延伸閱讀