WS-I takes on security challenge

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
A group working to ensure the compatibility of Web services software is preparing to tackle its biggest challenge yet: security. The Web Services Interoperability organisation (WS-I) was formed last year at the behest of companies including IBM and Microsoft to see to it that Web services products from different companies work together. The group now has approximately 160 members, including about 20 companies that are not information technology suppliers. Although businesses are forging ahead with Web services applications as a way of bridging differences between disparate systems, minor incompatibilities are surfacing. The WS-I's stated goal is to make sure gear from various IT suppliers is compatible and to help customers iron out any Web services glitches. So far, the group has delivered a draft specification of basic Web services protocols, which is set to be finalised in the second quarter. But to date, the WS-I has been better known for various political squabbles than for technical leadership. A high-profile spat between Sun Microsystems and its founding members has generated most of the attention for the group. After initially being shut out by founding companies including IBM, Microsoft and BEA Systems, Sun subsequently joined the organisation. Now the WS-I is intent on making its mark in a more meaningful way. In March, the group will formally tackle the thorny issue of Web services security, which analysts say remains an imposing roadblock to the technology's adoption. The WS-I will create a number of technical working groups that will recommend how IT providers and businesses should choose from several Web services security methods to match different business scenarios. "The industry is focused on what we're doing to a very great extent," said Tom Glover, chairman of the WS-I and a programme manager for Web services standards at IBM. "Standards alone don't guarantee interoperability." But despite its laudable intentions, the WS-I faces challenges -- both technical and political -- as it tries to establish itself as an influential Web services standards arbiter. Corporations like United Airlines, Merrill Lynch and DaimlerChrysler, joined the organisation last year because of the stated "vendor-neutral" stance of the WS-I. Businesses want to use Web services, but they don't want to have to debug incompatibilities between supposedly standardized products. If the WS-I mission misfires, Web services standards progress could stall and disillusion both IT providers and their customers, analysts warn. "At any step along the way, if someone is not adhering to the specification, then the chain becomes only as good as its weakest link," said Stephen O'Grady, an analyst at RedMonk. For example, when businesses rely on Web services to exchange data between business partners, they need to ensure that a transaction will not break down because of a software incompatibility, O'Grady said. Getting down to business
The technical work at the WS-I until now has focused on its "basic profile," a series of guidelines, sample applications and tools to test product compatibility. The basic profile has been in draft form since last fall and is expected to be completed by the second quarter this year. It addresses the first Web services standards written, including XML document definitions, Simple Object Access Protocol (SOAP), Web services Description Language (WSDL), and Universal Description, Discovery and Integration of Web services (UDDI). In taking on the hot-button issue of security, the WS-I has its work cut out for it. Matching numerous overlapping proposals for security standards to a huge number of business usage scenarios makes for a complex undertaking. For example, a Web service for accessing customer information internally may not have the same stringent security demands as a Web service that transmits sensitive data on customer accounts between financial institutions over the Internet. The WS-I intends to give corporations guidance on how to use security effectively with Web services in different business situations and clarify any ambiguities in the security specifications for IT providers. The WS-I is not a typical standards organisation because it doesn't design the base level specifications for Web services products. Still, as past experience shows, it's clearly not immune to the political wrangling present in most multicompany collaboration efforts. WS-I members are already campaigning for a seat on the WS-I's board of directors in an effort to exert more influence on the future direction of Web services. Last week, Web services start-up Cape Clear Software said it would run for election to the WS-I board of directors in March in an effort to promote "transparency and accountability." Cape Clear noted that the great majority of the WS-I's 160 members are small to medium-sized Web services companies but that the smallest company on the board has an annual revenue approaching $1bn. Cape Clear said it is concerned that large companies in the WS-I will be tempted to steer Web services standards to favor their entrenched businesses and products. "Smaller companies have much less of an agenda, and an ability to keep the others honest," said Cape Clear chief executive Annrai O'Toole. "We'd like to prevent the (WS-I) from becoming a cartel moving the technology to suit a cozy few." WebMethods, which is a medium-sized integration software maker, also plans to run for the board. The WS-I's Glover contends that the group is not simply rubber-stamping the dictates of its largest members. Glover points to the fact that the largest vendors have had to rework and delay releases of their Web services wares to hew to the WS-I's basic profile. Sun, for example, had to rework the crucial 1.4 update to its Java 2 Enterprise Edition (J2EE) to comply with the WS-I's basic profile. Sun released the Web services-ready Java specification after a three-month delay. Despite such inconvenience and potential lost revenue, however, the first "deliverables" from the WS-I have garnered the hoped-for industry support. However, the WS-I faces the vexing issue of enforcement, particularly as it steps up the pace of its recommendations this year. Being members of a voluntary organisation, companies are not legally bound to follow the WS-I's lead. "Frankly, that's a question that the board grapples with," admits the WS-I's Glover. "Right now we're expecting the community to pretty much police themselves." The WS-I is toying with the idea of a logo programme. The model would be self-certification: after IT companies follow the WS-I's implementation guidelines and run the appropriate tests, they could certify themselves, affix the WS-I logo to their products and make their claims publicly available. The WS-I is also looking beyond security and discussing the creation of committees to consider Web services standards around reliability and business workflow. The trick, say industry observers, is making sure the WS-I addresses real-world implementation issues and doesn't overcomplicate Web services standards. With future IT industry growth hinging in large part on interoperable and secure Web services, the WS-I faces a crucial proving period. The next year will show whether the WS-I will be remembered as a worthwhile experiment at standards consolidation or another standards initiative that falls short of expectations. "Once the WS-I starts diving into the meat of things, like security, messaging, reliability and transactions, the question becomes whether it will get the support of vendors -- and will they have the compliance schemes," said Ron Schmelzer, an analyst at ZapThink. "That remains to be seen. And in order for it to work, it can't be a political process."
What standards will drive the next wave of Web-based services, and how will they interact? Check out the latest developments on .Net, Java, Liberty Alliance, Passport and other technologies at ZDNet UK's Web Services News Section, including analysis, case studies and management issues. Let the editors know what you think in the Mailroom.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

3 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

5 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

5 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

6 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

7 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

8 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

8 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

9 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

9 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

9 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

10 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

10 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

10 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

13 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

14 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

14 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

16 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

17 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

18 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

1 day ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility