On TechRepublic: 12 tech terms that make you sound old
BNET Business Network:
BNET
TechRepublic
ZDNet

August 19th, 2008

IBM's Raj Nagaratnam: SOA services have identities, too

Posted by Joe McKendrick @ 9:26 am

Categories: General, Links, Management, Vendor Watch, Web Services

Tags: SOA, Service, Identity, IBM Corp., SOA Security, Service-Oriented Architecture (SOA), Web Services, Middleware, Enterprise Software, Software

The ability to build trust into SOA-based transactions – and therefore, security SOA Security podcast– was the subject of a recent podcast discussion I had with Dr. Raj Nagaratnam, IBM distinguished engineer and chief architect for Identity and SOA Security, posted over at the ebizQ site. SOA security is a hot topic these days, and companies are just starting to kind of get their arms around exactly how they can secure their emerging SOA implementations.

In my discussion with Raj, we talked about the emerging security issues he sees developing as SOA becomes a mainstream part of IT and the business.

A couple of themes emerged. First, that trust matters more than anything in SOA. Not only do consumers of services need to trust that these services are stable and secure, and second, because both users and applications will be either be providing, or accessing and consuming services to other applications and users far from their original domains.

The second theme of the discussion was how pervasive identity management needs to be. Not only do end-users need to be authenticated and validated in a global way for transactions, but since SOA is all about application-to-application or service-to-service interactions, services need identities as well.

While SOA surfaces many of the same security issues enterprises have become familiar with in recent years, it adds a new dimension to these concerns. While traditional approaches required locking down a single application, database, or network, SOA’s loose coupling of services and application across many domains make security a little more complicated.

“Given SOA enables loosely coupled approach to services and reuse, what happens is when you interact with partners, consumers, and providers, any exemptions you had about the control are about to change,” Raj explains. “Most importantly, trust in the environment changes dramatically. So trust-based identification and identity management is key.”

Raj outlined five key areas that need to be addressed in the realm of SOA security:

  1. Trust and identity: “Enterprise boundaries are expanding, therefore managing trust becomes important. Applications are no longer within a firewall. So in that context, identities need to be trusted, mediated, and managed.”
  2. Services have identities, too: “In an SOA environment, identities are not limited to user alone but service themselves. Services start to have or need to take on identities themselves because services in a composite application environment; one service may invoke another service. A shipping service may be invoked by an order processing system. So in this context, services take on identities so the life cycle of services as well as users need to be taken into account when considering identity.”
  3. Data itself needs greater protection: “There’s greater focus on application and information assets, because information such as medical records or financial information, could potentially be exposed outside. Protection measures need to apply to manage and enforce the data, whether its data in transit or data at rest.”
  4. Compliance: “Compliance needs to be a key driver that for the ability to know who accessed what, and who has access to what, and things like that to provide audit reports such as with compliance. This is important in an SOA environment. The challenge is around these audit reports and logs are not the systems you control but it could be in other systems. Effort becomes more important.”
  5. Policies: “In the adoption of SOA, people are thinking about individual services how to reuse them but they’re moving to where it’s a model where multiple services could be composed to traditionally security measures that oriented towards a single application or a service. But then, we compose these multiple technology services into business services and policies need to be managed at a very high level and not just at technology like a web service level but holistic business service level. The policy driven approach is going to become more important and there’s lot more work to be done in this area.”

Full transcript of the discussion available here.

Joe McKendrickJoe McKendrick is an author and consultant with deep knowledge and insights regarding trends and developments in the technology industry. See his full profile and disclosure of his industry affiliations.


Email Joe McKendrick

Subscribe to Service Oriented via Email alerts or RSS.

Talkback

Add your opinion

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
The more you simplify, the more you save
When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
Learn more about tools to grow your business
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Save time with the UPS Business Essentials Guide
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline