W
E
B
S
E
R
V
I
C
E
S
E
R
C
U
R
i
T
Y
W
E
B
S
E
R
V
I
C
E
S
E
R
C
U
R
i
T
Y
GVHD: Nguyễn Văn Hoàng
Mục lục
! "#$
%"
&' (
Lời mở đầu
•
)* +,#-!+./"01 2 ,3(% "'%4
1 %5 "6 %(37801 97:3 (% (;"
<02=<7>1
•
%-1-,=<? "3@16-A"76 %(387- %6 "
#$01 9+B=C"D1%?E(F !6-A"
•
)*"G%-@1 7+ 1.01 2'A"1 %
1H "#$I:J7K"#D=<1 % -3 C7"+"G/"6
4 (;"<%- "L "1"%1(>" "%"0L2-(%
/6"@1"1""3/
MD "4D%-1-%3"!N(%=14 >1 O=
= C 1(>"(B5" "L3"!N4(%=11(>=<1 %
"O==P(% "G01 9"
Nội dung
•
)"Q"";1@1RMS(M=$T7
=(% "3 "C/"+B "' K'4
"U BK"8 +V 6G16NW !66
-A"K"6"1 "#01> 713"
%=<XK' @1D+B# YZI
•
=(% /6/"+V "N+B "<"3
"#01 /"+V "N[\%+B=EW4 >
6NW/"2 6
•
&"#/"W "%#G(/ L"7 -/ K]NW%
•
^U B "1 6G16 "%"/"K"#_" 7"/"5/"6 4 "/%` L
•
&"#/"W "%#G(/ L"7 -/ K]NW%
•
^U B "1 6G16 "%"/"K"#_" 7"/"5/"6 4 "/%` L
•
MDK"8NW !6 71 "N%Q"1G(3<1 !2!`%"4721
K"8 6=EW
•
)>,01"3 +V 6a/"3/"6 4`%
•
)"ab-"3 "CA""B/7=</"N >/@1"3 "C7">6 "%""> 7/"6 4"3 "C"1"% +V 6
"30,"3 "C@161""3/K"67c
•
MDK"8NW !6 71 "N%Q"1G(3<1 !2!`%"4721
K"8 6=EW
•
)>,01"3 +V 6a/"3/"6 4`%
•
)"ab-"3 "CA""B/7=</"N >/@1"3 "C7">6 "%""> 7/"6 4"3 "C"1"% +V 6
"30,"3 "C@161""3/K"67c
•
"G "3 ">(,=d?-1%K" "1"' @1=713K"# "1-H7D "4(U' 6-
K"6"K"#+B2/7 "'61 "N"3"%"
•
MD06""b"=K"'+JK"DXX 7'1 %%
•
"G "3 ">(,=d?-1%K" "1"' @1=713K"# "1-H7D "4(U' 6-
K"6"K"#+B2/7 "'61 "N"3"%"
•
MD06""b"=K"'+JK"DXX 7'1 %%
!
/(ef ==g (hi1
"N -/C +BVT
%1 "N "1-H6 "#3/<1
!ZI01>6-A"7 "#
"+=EW1 "N^))g
"#
j=/$11k#
G# 6Q"W
lQ"";16"# = "
a/"6/ H06 @1ZI
j "++B=EWK' "B/,
ZI="1%eg4/
=01
$""
[=1(j=/$7j=-1
1$k)5""B/7K"6/"6%#
18
lQ"";1 =C "%"/""'
6 "#$%-7"/"m/6( -
n%""G "#$+B-!
K"=EW=
Cấu trúc tổng quan của Web service
Cấu trúc tổng quan của Web service
•
=(% 6""b4A""B/6NW !OSk1=1//(1$=T
•
M6NWD "4=EW6 "%"/"K"6"14 > "%" Q"W7M6 "%"/"%-
+B9/"+V "NegS&"6/"+V "Nge)7io)T!K"#Q://"pO1((K" -
? 6 "%"/"!%6-"@
%&'()*&+,
•
l4?2-< O=7"a 1 "<"36+,=1q
Bước 1 qlQ"";1%?2-<6"N876Q"W%==d
/S=EW#Gr11"s">T
Bước 2 : )>j"=
Bước 3 qZ2-<eg="=
Bước 4 ql8KFj,[jj= -4"/"m/6( D "4n
"-% -?
Bước 5 qM( "p(j% *D?2-<eg( 4D "4K'
C,eg=
Bước 6 qZ2-<NW/"51( S"s">=EWr11T%=1D
9 "<"3= "#013K' C ,eg=
/
•
%-1-=1 /"6 47"G(;"<
=CD "46/W%A""B/=(%
K"6(,"+Q"W"9(9%/"2(>$ NS"3
"C "+3DK' C'O/ 1(4nK'6
"#$ "' Tt
•
NW"6Q"W(Q"S/6m7 "#$
Q14cT76>(F6"%01>7 "#$
"+V>"+67 u6"C67601>c
"1-Q"W1Q" < -'S"v%vMT"+
: m6-1-7 "#$ "!?c
0122'345''6'78
•
)01" "'Ku7"%(> 61 "N%V"'.+B >1"Y6/N"
1 %% "#$ % "#$. "1-H " "1
2-)+,K1""+"wD" "#$71-x"y "!"-!
,"+1"6-"@% !>
•
lC,U"3 "C "#$C91%"0$b(%
(,
9:;<'9'789+=>5?382@A>1'A:BCC')1'DE''FG&6
*H
•
)*/"51+=EWq?2"/ "B//"6/78X/ %=D6 Q
•
)K' a"3 "C "#$q H"N"3 "CKz " K"#D a"
:K"#@>"43 "#$
•
1- "5"=6" 1 % "#$qK"#"/"%"6"b1
%7K"#?6Q"{60- "%""3 "C
•
)"#$ "3 "C6-A"P=d`Q?2"/'K"#D#W
0(F7K4 1%K"4"3 "C
•
-VY1- a/"N@16 "' Q$"9% /"
"3 "C%NW".=? %=|6(>}3/~3 E "F
_Q" +,79(%}3 E~
•
-"4" C,>6-A"(%$ :7 */"519 /">
) "!7W$!@1 K"#"wYD9 (;"<3 "#
$%x"/"> JK"6"+K4-3 O7 7
"•/7 !6"3 "C "1" 63 E%1Q" < -'c
'4>4
1.
An toàn cho Web service:
•.
)*"G%-@1 7+ 1.01 2'A"1 %
1H "#$I:J7K"#D=<1 % -3 C7"+"G/"
6 4 (;"<%- "L "1"%1(>" "%"0L2-(%
/6"@1"1""3/&"#D N1 % "5""B/7
=<K"1 "6 "+V>@1 "LK"#"% %1 %
•.
i2-76Q"WO. ""a +B%-%"C01 2
" */"51_jQ"W(!K' % +V 6,6NW0
1 7"5"L- (% +B01 2K"6# -
$' ,K' "B/NW, Q"W
'&
•
k -(% "b1 %1 J"eg%"G/"
@1eg7D+BJK"C?2-<"GO= %€%$
-D+B "' K'1A""YD "4"+, ,"G#"L"1
%K"61_g&7&=7%
•
= -/""U B""V"'1 %K"6"17"K"
#>"GKF7%"#"3."D1D"A"1 %7=<
%€ "#3/7%A"$-@1 "#3/
•
O== -"w(% (,/ "(,/@1 /"6/1 %O=
M"N "< NW
•
M/ "31 %
/$#
•
M"w{ 1((1K"1(
/$#
•
M/ "31 %
/$#
•
M"w{ 1((1K"1(
/$#
•
l4"L"=1 %D
"31 %"B/(3
•
M"w{ 1((1K"1(49
"31 % -!%=1
D?6"D
•
l4"L"=1 %D
"31 %"B/(3
•
M"w{ 1((1K"1(49
"31 % -!%=1
D?6"D
Phía client
Phía Server
G:I'J''K4,'4>'78'4L'M+.
( %=/"DA" %€ "#$
•
M"w{"G "%"/"@1==1%
/"D"GKF"1- "3"N "<
%D
•
M"w{ K"D1 !"3 "C /$%=dKF
(!==1
•
M"w{"G " =d+B=EW
K"D14KF(!==1
•
/"+B"L"4(%"D"3(<
A" %€@1==1/""_
•
M"w{"G "%"/"@1==1%
/"D"GKF"1- "3"N "<
%D
•
M"w{ K"D1 !"3 "C /$%=dKF
(!==1
•
M"w{"G " =d+B=EW
K"D14KF(!==1
•
/"+B"L"4(%"D"3(<
A" %€@1==1/""_
•
M"w{"G "%"/"@1==1
+BKF
•
M"w{ K"D14-3 "GKF@1
==1'?D"B/(3"1-K"#
•
M"w{ " %K"D1=EW(%"
D"3(<A• %€@1==1E
'
•
/ "#$"GKF ==1
/""_
•
M"w{"G "%"/"@1==1
+BKF
•
M"w{ K"D14-3 "GKF@1
==1'?D"B/(3"1-K"#
•
M"w{ " %K"D1=EW(%"
D"3(<A• %€@1==1E
'
•
/ "#$"GKF ==1
/""_
Phía client
Phía Server
Các hình thức đảm bảo an ninh dịch vụ web
Bảo đảm an ninh ở mức truyền tải
•
%V"'1"4 ,4Sg g T7J"
3">%?6 "<6!7A" x1€%
@1 "#3/
•
^))g(%1 "NK"#1 x17G(3+B -
>)? !`Q(
•
&z " ^))g"/"m/?6 "<6-"@76-"@/"?
L""N "<" L"K"6"4 L"K"6""
>6-"@
)"< '+ 1 "+J?6 "<V=^))gK' "B/
,^))g
Bảo đảm an ninh ở mức thông điệp
•
%6"$'/(% "#$(!01 ,1"
+BDK5 eg
•
1"N "#3/x"y=<3Y
"‚% !+J7 .ZI%"GKF=C
•
l: 1"Q"WSk -T
/1"N "#3/
)"++BK' "B/,1"N ]!
G'>DINL'&
•
O== -"w(% (,/ "
(,/@1 /"6/1 %O=
-@7! #"L"1 %"(,
"V4D "41/"@ 6K"51>"1
%K"6
•
)#"L"%-6 "%"/"01 9
1_q
G'>DINL'&
•
kM=1$j==q"/"m/0(F%?6"
==1 1HG16/"71_=< 1HG"1
%7 "' (/7ƒ? 1"G===
•
k "$1$j==q"/"m/0(F"GG(3
"N "<%"5"=6""N "<
•
kg(-j==q"/"m/0(F"G%@1"G
"5"=6"1 %64 1%C
•
k)= j==qK""/"m/"GO=1 %
1H7 +V 6,"1
I "b1 %""6"3 "C1Q" !> "+/" / %
•
$p1$qQ"1"+B"G1 -/ %-!"3 "C
•
"$1$q"N "< +6" -/ %-!@1+C=EW
•
"„1$q"/"m/1Q"K".?6"Q"1"+ -/
•
-q %€ "#$ !+ -
•
Mp$1( -q1 %7K"#1D "49 "#$ !+
•
$qK4 17 61Q"+B(+(>4K4 1
•
k/1$q‚7"/"m/"N "<"B/A""B//"6/"D1@1 "#$' * /"51 "N1%v/"51(
%+E%+"
"G-! !a/""3 "C1 %"V7 6"+B/"%"G -/K"#"B/(3
I "b1 %""6"3 "C1Q" !> "+/" /
%
^))gh^-/)? )1=…g ((%1 "N "+=EW" "3 1H "#$ ! 7 -"!(>(%
1 "NK"#1 %7L "#$+BE+,>8 >1"%K"#1 %
I /"6 4@1^))g(%^))g7D(% "b1 %"^))g7^))g"/"m/"N "<( %=01"G
"N "<G1( %=
^))g/=<1 % , %DG(3^))g
I:J^))gK"#1/"@ 6K"51>" "b1 %"7"+DP./ N"N
-@,Q"1"%"N "<7=< %€ "#3/7%$-
)-"!71 "$1$71$71k/1$"+1+B/!>"D7^))g(% 1 "N!K" "#
3/01^))g= "L(>K"#1 %
KẾT LUẬN
•
%-1-#"3O==.%1+B 4K"1%NW "(;"<K"6"11_"G
(;"<">-7x"yA"1 %1"+ %"5"72"%7cDO=/ N1 %@4
"U B"G#3"+ "'
•
=E=WO== -%6 "%"/"@1Da/" "#$ 1H !O== !1 %"V7 -"!3
"9V"'1 %"O=/"x"y=1"+JK"# "-0a1/"N >/ > =<xD
•
lD3"9V"'1 %% O== - "L/"W ""%(>=%"GA"8%=%-
/
•
!>"Dx 401 2D(%=<1 %K"#"w/"W "%"G " 7"G$!"b7%"G
V"'%O== -1(>7%Dx J-% "6@16# -D"4{ 01 9@11 % "#$K"
4K"16NW71Q" !>"1-K"#P "'
T
h
e
e
n
d
!
!
T
h
e
e
n
d
!
!