Sun sets pace for Web services security

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Sun Microsystems, sensing it has fallen behind rivals Microsoft and IBM in Web services leadership, is launching a renewed strategy in an attempt to play catch up. Senior Sun executives have issued an edict to internal programmers to quickly create a software "framework" that addresses what they see as potential security weaknesses in existing Web services standards, a source familiar with the plan said. Sun has begun sharing details of the framework with potential partners and is working as quickly as possible to have an announcement ready by late summer or early autumn, sources said. The company has already quietly published one new standard for streamlining Web services, and is beginning work on a security specification intended to make Web services less vulnerable to computer attacks, sources said. Some of the work mirrors existing specifications introduced by Microsoft and IBM, analysts said. "Sun is trying to match them tit for tat and to help keep themselves in the mindshare of people thinking of Web services," said Gartner analyst Daryl Plummer. On Wednesday, Sun is also expected to announce improvements to its Sun Open Network Environment (Sun ONE) application server and other software plans. A Sun representative declined to comment on the Web services work. "Right now, it would be a rumour, and we don't comment on rumour or speculation," said Sun spokesman Russ Castronovo. Representatives from Microsoft were not available for comment. An IBM representative said the company is forging ahead on its own previously announced plans. While the renewed focus on Web services by Sun could result in technology that's urgently needed by big companies, the move escalates the showdown between rival camps, and could derail the much-hyped Web services push, already beset by industry squabbling. Web services promise to make linking internal computer systems, and systems residing in multiple companies, far easier than current methods. "Sun needs to come up with an understanding with Microsoft and IBM, so they're not constantly competing on standards," said analyst Shawn Willett, of Current Analysis. Sun tries again
Sun's previous attempts at defining a Web services strategy have been characterised by a series of fits and starts. While Microsoft has been the most vocal technology maker in the Web services arena, largely defining the playing field for its competitors, analysts have criticised Sun for being late to announce a Web services strategy. Sun executives have admitted that the company has been slow to stake its claim in the Web services area. It hasn't always been this way. Sun starred in the first phase the Internet's growth, selling powerful networked server computers while Microsoft and IBM played more peripheral roles. But the two came back fighting with Web services, and now Sun is trying to reclaim the initiative. Sun has been battling Microsoft and IBM on Web services almost from the start. Microsoft, along with IBM, co-founded the Web Services Interoperability Organization (WS-I), which aims to promote Web services by ensuring that software from technology makers is compatible. More than 100 companies have joined, but Sun has declined an invitation to join as a contributing member, campaigning instead for more influential "founding board member" status so it can help set the group's agenda. During the Microsoft antitrust trial, evidence surfaced in written testimony that chairman Bill Gates and other Microsoft executives attempted to steer the direction of the WS-I away from Sun. Meanwhile, Microsoft and IBM have forged ahead. Just last week, Microsoft said it is building additional Web services security software in the hope of reassuring big companies now assessing the technology for future projects. Meanwhile, IBM continues to revamp its tools and application server software to form a more cohesive package for Web services development. The partner principle
In its latest Web services effort, Sun hopes to enlist other companies as backers. That technique has proven successful in the Sun-spawned Liberty Alliance Project to counter Microsoft's Passport authentication service. Sun plans to eventually submit its Web services work to a standards body such as the Organization for the Advancement of Structured Information Standards, or OASIS, a consortium developing electronic business standards, or the World Wide Web Consortium, which also administers standards work from Microsoft and IBM. Sun's new specification for streamlining Web services is being developed in partnership with BEA Systems, SAP and Intalio. The specification, called the Web Services Choreography Interface, or WSCI, is a mechanism for describing what messages are sent among computers as a particular Web service is processed. The choreography standard mirrors similar work already underway. Microsoft and IBM have built competing languages called Xlang and Web Services Flow Language (WSFL), respectively, and industry groups such as OASIS and the Business Process Management Initiative ( BPMI) are working on their own standards. Sun's WSCI partnership might dovetail with the BPMI work, though, since its partner Intalio is BPMI's founder. Sun also plans to devise a security specification for Web services. The security work might at first blush seem to tread on the toes of the WS-Security initiative, one of several created by Microsoft and IBM. But that initiative is concerned more about security in the sense of encrypted communications and transactions, whereas Sun's appears to involve security in the sense of computers that can't be breached by attackers. But questions remain about how the specifications will coexist. "The question is how will WS-Security and Sun work together? This is another example of fragmentation if they're not going to work together and are just competing," said Gartner's Plummer. Security has surfaced as one of the most critical areas of Web services. Larry Kittelberger, chief information officer for Honeywell, said his company is evaluating Web services, with security among the biggest concerns. Kittleberger said Honeywell, a conglomerate that makes everything from aerospace and aircraft parts to fire detectors, is working to digitize its businesses. "If I'm going to put 90 percent of our corporate processes online I want better security," he said. "That standard has got to get hooked up." Specifically, Kittelberger said he would like a security architecture that allows "detective" security. "I want it so hackers don't know if they've fallen into a soft area or a trap," he said. "It has to be more than just a big fence." News.com's Wylie Wong, Larry Dignan and Mike Ricciuti contributed to this report.
More enterprise IT news in ZDNet UK's Tech Update Channel.

For a weekly round-up of the enterprise IT news, sign up for the Tech Update newsletter. Have your say instantly, and see what others have said. Go to the ZDNet news forum. Let the editors know what you think in the Mailroom.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

bootlegger

Make that 13 people now - I got refused today at Manchester airport. I thought I was up to date on this legislation - I knew of the EU ruling from...

2 hours ago by bootlegger on UK airport body scans will not be opt out
tinycg

Don't forget to check out apps like GoodReader or SlideShark either, they're indispensible for people on the go in presentation situations. Best...

5 hours ago by tinycg on Four top iPad apps for people on the move
TerryRK

Well it seems there is something a number of us agree on. Why is the Ubuntu Unity launcher so ugly? I thought perhaps it was something to do with...

10 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

19 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

1 day ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

1 day ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

1 day ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

1 day ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

1 day ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

2 days ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

2 days ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

2 days ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

2 days ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 days ago by bdantas on A tale of two distros: Ubuntu and Linux Mint