RE: Security Question
Hao He <[email protected]>
| Newsgroups | gmane.comp.web.services.ws-arch |
|---|---|
| Message-ID | <686B9E7C8AA57A45AE8DDCC5A81596AB019ED8CA@sydthqems01.INT.TISA.COM.AU> |
Is this an ownership issue? Simply put, you don't link to a schema that is not under right ownership and security. In Roger's example, the purchaser can simply link to a schema owned by the seller. Hao -----Original Message----- From: Krishna Sankar [mailto:[email protected]] Sent: Tuesday, August 06, 2002 4:47 AM To: [email protected] Subject: RE: Security Question Roger, Actually a good question. a) Normally, the purchase order, which would be the payload and based on a schema/namespace. For example Rosettanet PIP3A4 Version x would say what the qty mean, how one can add the qualifier "each", "lot",... et al and also what the default value is. If there is no default value, then the PO would be rejected, .... you get the picture. The PO would be signed and that is how we assure integrity. Of course, for confidentiality, we would encrypt the PO as well. In short, the context, in this case the namespace and the schema would be captured in the message and signed to assure integrity. b) Reading thru your e-mail, are you talking about an alteration of the schema at the buyer side ? Were you thinking of creating a PO using one schema and then sending it out with reference to a similar but different schema ? BTW, this could happen by mistake as well - for example create using Version 1.0 and then send with a ref to version 2.0; and extending the contrived example, ver 1.0 says "Each" and 2.0 says "doz" as the default :o(. BTW, this is not a case of sending a Version 1.0 message to a version 2.0 web service because the version 2.0 service would fault if it cannot handle the semantics of the 1.0 message. This is where version number plays a big role. cheers -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Cutler, Roger (RogerCutler) Sent: Monday, August 05, 2002 11:18 AM To: [email protected] Subject: Security Question I've got a question about security that may reflect some misconception on my part -- but here goes anyway: I think that the XML payload of the response from a web service -- or indeed I suppose the message that invokes it -- may be validated by a schema. If so, that schema can add data via defaults and/or fixed values. How is this secured? Let me be more specific with a contrived example: Suppose we are purchasing widgets via a web service and in the XML document you specify "1" for the amount to purchase. However, suppose the schema has a default value of "Each" that explains the meaning of the "1". Now suppose that either from malicious tampering or through the use of a schema intended for a different audience that default (which is on the seller side) is changed to "dozen". Now the "1" really means 12 items, which is a lot more expensive. This is obviously contrived and dumb, but I think it illustrates the fact that schemas can affect data. So how is this secured? Can the buyer in the context of the message unambiguously specify what schema must be used for validation and have some sort of check that it was the right one? Can it be secured?
InterScan_Disclaimer.txt
(text/plain, 438 B)
===================================================================== WARNING -This e-mail, including any attachments, is for the personal use of the recipient(s) only. Republication and re-dissemination, including posting to news groups or web pages, is strictly prohibited without the express prior consent of Thomson Legal & Regulatory Limited ABN 64 058 914 668 =====================================================================