Abstract:WS-Security provided a total framework for web services, but it is only abstract standard. On the basis of WS-Security, experts in IBM Tokyo laboratory bought forward Session Authentication Protocol which would be new solution for session entity authentication. In the paper, we give security defects of the original protocol, then make some improvements by selecting Diffie-Hellman algorithm improved with PKI certificate as new key-exchanging mechanism.
scite is a Brooklyn-based startup that helps researchers better discover and evaluate scientific articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by researchers from dozens of countries and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.