background image

OASIS Specifications

<< Web Services Security Initiatives | JCP Specifications >>
<< Web Services Security Initiatives | JCP Specifications >>
OASIS S
PECIFICATIONS
237
and guidelines. The W3C is working on the following specifications related to
web services security:
· XML Encryption (XML-Enc)
This specification provides requirements for XML syntax and processing
for encrypting digital content, including portions of XML documents and
protocol messages. The version of the specification current at the time of
this writing may be viewed at http://www.w3.org/TR/2002/REC-xmlenc-
core-20021210/.
· XML Digital Signature (XML-Sig)
This specification specifies an XML compliant syntax used for represent-
ing the signature of web resources and portions of protocol messages
(anything referenceable by a URI) and procedures for computing and ver-
ifying such signatures. The version of the specification current at the time
of this writing may be viewed at http://www.w3.org/TR/2002/REC-xmld-
sig-core-20020212/.
· XML Key Management Specification (XKMS)
The specification specifies protocols for distributing and registering pub-
lic keys, suitable for use in conjunction with the W3C recommendations
for XML Signature and XML Encryption. The version of the specification
current at the time of this writing may be viewed at http://www.w3.org/
TR/2005/REC-xkms2-20050628/.
OASIS Specifications
According to its web site at http://www.oasis-open.org/, the Organization for the
Advancement of Structured Information Standards (OASIS) drives the develop-
ment, convergence, and adoption of e-business standards. OASIS is working on
the following specifications related to web services security. At the time this
document was written, OASIS standards documents are available from http://
www.oasis-open.org/specs/index.php.
· Web Services Security (WSS): SOAP Message Security
This specification describes enhancements to SOAP messaging to provide
message integrity, message confidentiality, and message authentication
while accommodating a wide variety of security models and encryption
technologies. This specification also defines an extensible, general-pur-
pose mechanism for associating security tokens with message content, as