26.04.2014 Views

leader replacement system - Department of Public Social Services ...

leader replacement system - Department of Public Social Services ...

leader replacement system - Department of Public Social Services ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Los Angeles County<br />

<strong>Department</strong> <strong>of</strong> <strong>Public</strong> <strong>Social</strong> <strong>Services</strong><br />

LEADER Replacement System (LRS)<br />

639<br />

640<br />

641<br />

642<br />

643<br />

644<br />

645<br />

646<br />

647<br />

648<br />

649<br />

650<br />

651<br />

652<br />

653<br />

654<br />

655<br />

656<br />

657<br />

658<br />

659<br />

660<br />

661<br />

662<br />

663<br />

664<br />

665<br />

666<br />

667<br />

668<br />

669<br />

670<br />

671<br />

672<br />

673<br />

674<br />

675<br />

676<br />

677<br />

678<br />

679<br />

680<br />

681<br />

682<br />

683<br />

• Transform message formats between requestor and service.<br />

• Handle business events from disparate sources.<br />

Some ESB vendors include additional features:<br />

• Service composition<br />

• Business process management<br />

SOA Security<br />

Because SOA is XML message-based, security in the SOA world is handled via specific<br />

sections within an XML message. WS-Security from OASIS defines the mechanism for<br />

including integrity, confidentiality, and single message authentication features within a SOAP<br />

message. WS-Security makes use <strong>of</strong> the XML Signature and XML Encryption specifications and<br />

defines how to include digital signatures, message digests, and encrypted data in a SOAP<br />

message.<br />

Identity and Authentication<br />

Authentication means verifying the identity <strong>of</strong> a user. The Web service security standards allow<br />

for the notion <strong>of</strong> identity authorities and trusted relationships. That is, an identity service can be<br />

federated among departments; however there is only one authority for a given type <strong>of</strong> identity<br />

(for example, a Citizen Authority which would be the single point <strong>of</strong> authenticating any citizen<br />

performing an interaction requiring security). Other citizen-based applications would trust this<br />

authentication and not re-authenticate as the user’s interactions invoke different applications.<br />

SAML (Security Access Markup Language)<br />

Security Assertion Markup Language (SAML) from OASIS provides a means for partner<br />

applications to share user authentication and authorization information. This is essentially the<br />

single sign-on (SSO) feature being <strong>of</strong>fered by all major vendors in their e-commerce products.<br />

In the absence <strong>of</strong> any standard protocol on sharing authentication information, vendors normally<br />

use cookies in HTTP communication to implement SSO. With the advent <strong>of</strong> SAML, this same<br />

data can be wrapped inside XML in a standard way, so that cookies are not needed and<br />

interoperable SSO can be achieved.<br />

SAML is an XML vocabulary that defines the syntax necessary to exchange identity information<br />

between applications.<br />

Security Standards<br />

There are many Web service security standards. Please see the Security Standards for Web<br />

<strong>Services</strong> section in the SOA Security White Paper for detailed descriptions.<br />

Reference SOA Architecture<br />

Establishing an Enterprise Reference Architecture is important for the big picture. SOA is a key<br />

subset <strong>of</strong> the enterprise and it is sometimes not obvious where SOA fits into the enterprise.<br />

That is, one can get lost in the many details and standards surrounding SOA. So, a Reference<br />

SOA Architecture is provided (see following diagram).<br />

LRS RFP - Attachment H (Technical Exhibits) Page 28 November 30, 2007

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!