Microsoft bolsters Web services security

The software giant releases a toolkit that lets developers use the latest security mechanisms in Web services specifications.

Martin LaMonica
Martin LaMonica Former Staff writer, CNET News
Martin LaMonica is a senior writer covering green tech and cutting-edge technologies. He joined CNET in 2002 to cover enterprise IT and Web development and was previously executive editor of IT publication InfoWorld.
2 min read
Microsoft released on Tuesday a toolkit designed to help software programmers tighten security in Web services applications.

The toolkit, called Web Services Enhancements (WSE) version 2, will let companies use the latest security capabilities from Microsoft and other software giants like IBM and Sun Microsystems. The software makers are bolstering security in an effort to drive adoption of Web services software.

Web services are a set of programming conventions and XML-based standards for building applications that can share information easily. Businesses are currently using Web services as a way to transport data between disparate systems. But tighter security for data transmitted via the Internet and private networks remains a barrier to wide-scale usage, according to analysts and customers.

WSE version 2 is designed to simplify the process of securing communications between parties and of ensuring the identity of people in a business transaction, according to Microsoft executives. The toolkit implements a number of security-related specifications that were co-authored by Microsoft, including WS-Policy, WS-SecurityPolicy, WS-Trust, WS-SecureConversation and WS-Addressing.

These published specifications, which are not yet widely adopted industry standards, are designed to work with Web Services Security, another Microsoft-backed security specification now being standardized at OASIS, the Organization for the Advancement of Structured Information Standards.

WSE version 2 is available from Microsoft's developer Web site. Eventually, Microsoft will add the capabilities to its Visual Studio.Net development tool and the .Net Framework, the software "plumbing" needed to run Web services applications on Windows operating systems.

Microsoft is using the latest Web services security mechanisms even though the various specifications are likely to change, according to Microsoft executives. However, the toolkit introduces a programming technique that will allow software developers and administrators to establish security policies that can be altered without having to rewrite existing code.

For example, a company could write a policy that would give network administrators access to corporate servers during working hours, but not after-hours. Using the policy authoring mechanisms in the WS-Policy and WS-SecurityPolicy, a developer can alter the policy without having to completely rewrite the application code, noted Rebecca Dias, product manager for advanced Web services at Microsoft.

The toolkit also introduces the ability to transport XML documents using several protocols, including both HTTP (Hypertext Transport Protocol) and TCP (transmission control protocol), which will make it simpler to build Web services applications for non-PC devices and wireless applications, Microsoft executives said.