Recently there have been a number of exciting developments in the area of Web
services security standards (SAML, WS-Security, XACML, etc.). However, unless
you are a security expert and closely involved in these standards, it is
difficult to sort through the alphabet soup and understand what each standard
is about. Do the standards address the same or different problems? How do
they interact?
This article seeks to clear up some of this confusion by illustrating how the
various security standards could be applied to address the security needs of
a particular business problem, in our case an open B2B process integration
platform that enables collaborative e-business and supply chain capabilities.
Yet we must note that these new security standards are applicable to any
distributed computing environment, from a multidivision secure intranet
portal to a group of public ... (more)