{"id":"https://openalex.org/W2007072126","doi":"https://doi.org/10.1145/1237500.1237504","title":"Secure sessions for Web services","display_name":"Secure sessions for Web services","publication_year":2007,"publication_date":"2007-05-01","ids":{"openalex":"https://openalex.org/W2007072126","doi":"https://doi.org/10.1145/1237500.1237504","mag":"2007072126"},"language":"en","primary_location":{"id":"doi:10.1145/1237500.1237504","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1237500.1237504","pdf_url":null,"source":{"id":"https://openalex.org/S2642811","display_name":"ACM Transactions on Information and System Security","issn_l":"1094-9224","issn":["1094-9224","1557-7406"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Information and System Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5026297326","display_name":"Karthikeyan Bhargavan","orcid":"https://orcid.org/0000-0002-3152-8997"},"institutions":[{"id":"https://openalex.org/I4210164937","display_name":"Microsoft Research (United Kingdom)","ror":"https://ror.org/05k87vq12","country_code":"GB","type":"company","lineage":["https://openalex.org/I1290206253","https://openalex.org/I4210164937"]},{"id":"https://openalex.org/I1290206253","display_name":"Microsoft (United States)","ror":"https://ror.org/00d0nc645","country_code":"US","type":"company","lineage":["https://openalex.org/I1290206253"]}],"countries":["GB","US"],"is_corresponding":true,"raw_author_name":"Karthikeyan Bhargavan","raw_affiliation_strings":["Microsoft Research, Cambridge, United Kingdom","Microsoft Research, Cambridge, United Kingdom ("],"affiliations":[{"raw_affiliation_string":"Microsoft Research, Cambridge, United Kingdom","institution_ids":["https://openalex.org/I4210164937"]},{"raw_affiliation_string":"Microsoft Research, Cambridge, United Kingdom (","institution_ids":["https://openalex.org/I1290206253"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5001567598","display_name":"Ricardo Corin","orcid":null},"institutions":[{"id":"https://openalex.org/I94624287","display_name":"University of Twente","ror":"https://ror.org/006hf6230","country_code":"NL","type":"education","lineage":["https://openalex.org/I94624287"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Ricardo Corin","raw_affiliation_strings":["University of Twente, The Netherlands","University of Twente, The Netherlands,"],"affiliations":[{"raw_affiliation_string":"University of Twente, The Netherlands","institution_ids":["https://openalex.org/I94624287"]},{"raw_affiliation_string":"University of Twente, The Netherlands,","institution_ids":["https://openalex.org/I94624287"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5108519702","display_name":"C\u00e9dric Fournet","orcid":"https://orcid.org/0000-0001-6929-886X"},"institutions":[{"id":"https://openalex.org/I1290206253","display_name":"Microsoft (United States)","ror":"https://ror.org/00d0nc645","country_code":"US","type":"company","lineage":["https://openalex.org/I1290206253"]},{"id":"https://openalex.org/I4210164937","display_name":"Microsoft Research (United Kingdom)","ror":"https://ror.org/05k87vq12","country_code":"GB","type":"company","lineage":["https://openalex.org/I1290206253","https://openalex.org/I4210164937"]}],"countries":["GB","US"],"is_corresponding":false,"raw_author_name":"C\u00e9dric Fournet","raw_affiliation_strings":["Microsoft Research, Cambridge, United Kingdom","Microsoft Research, Cambridge, United Kingdom ("],"affiliations":[{"raw_affiliation_string":"Microsoft Research, Cambridge, United Kingdom","institution_ids":["https://openalex.org/I4210164937"]},{"raw_affiliation_string":"Microsoft Research, Cambridge, United Kingdom (","institution_ids":["https://openalex.org/I1290206253"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5078684560","display_name":"Andrew D. Gordon","orcid":"https://orcid.org/0000-0002-5809-2484"},"institutions":[{"id":"https://openalex.org/I1290206253","display_name":"Microsoft (United States)","ror":"https://ror.org/00d0nc645","country_code":"US","type":"company","lineage":["https://openalex.org/I1290206253"]},{"id":"https://openalex.org/I4210164937","display_name":"Microsoft Research (United Kingdom)","ror":"https://ror.org/05k87vq12","country_code":"GB","type":"company","lineage":["https://openalex.org/I1290206253","https://openalex.org/I4210164937"]}],"countries":["GB","US"],"is_corresponding":false,"raw_author_name":"Andrew D. Gordon","raw_affiliation_strings":["Microsoft Research, Cambridge, United Kingdom","Microsoft Research, Cambridge, United Kingdom ("],"affiliations":[{"raw_affiliation_string":"Microsoft Research, Cambridge, United Kingdom","institution_ids":["https://openalex.org/I4210164937"]},{"raw_affiliation_string":"Microsoft Research, Cambridge, United Kingdom (","institution_ids":["https://openalex.org/I1290206253"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5026297326"],"corresponding_institution_ids":["https://openalex.org/I1290206253","https://openalex.org/I4210164937"],"apc_list":null,"apc_paid":null,"fwci":8.0831,"has_fulltext":true,"cited_by_count":47,"citation_normalized_percentile":{"value":0.9755728,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":"10","issue":"2","first_page":"8","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11504","display_name":"Advanced Authentication Protocols Security","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11504","display_name":"Advanced Authentication Protocols Security","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.9976999759674072,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":0.9940999746322632,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8665175437927246},{"id":"https://openalex.org/keywords/soap","display_name":"SOAP","score":0.8018841743469238},{"id":"https://openalex.org/keywords/scripting-language","display_name":"Scripting language","score":0.6978707909584045},{"id":"https://openalex.org/keywords/cross-site-scripting","display_name":"Cross-site scripting","score":0.6825156211853027},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.66512131690979},{"id":"https://openalex.org/keywords/web-application-security","display_name":"Web application security","score":0.576016366481781},{"id":"https://openalex.org/keywords/session","display_name":"Session (web analytics)","score":0.5518978238105774},{"id":"https://openalex.org/keywords/web-service","display_name":"Web service","score":0.5153655409812927},{"id":"https://openalex.org/keywords/transport-layer-security","display_name":"Transport Layer Security","score":0.5083231329917908},{"id":"https://openalex.org/keywords/ws-addressing","display_name":"WS-Addressing","score":0.4817247688770294},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.4425835609436035},{"id":"https://openalex.org/keywords/semantics","display_name":"Semantics (computer science)","score":0.4136383533477783},{"id":"https://openalex.org/keywords/web-development","display_name":"Web development","score":0.17714667320251465},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.1419476568698883},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.08949679136276245}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8665175437927246},{"id":"https://openalex.org/C17881449","wikidata":"https://www.wikidata.org/wiki/Q189620","display_name":"SOAP","level":2,"score":0.8018841743469238},{"id":"https://openalex.org/C61423126","wikidata":"https://www.wikidata.org/wiki/Q187432","display_name":"Scripting language","level":2,"score":0.6978707909584045},{"id":"https://openalex.org/C39569185","wikidata":"https://www.wikidata.org/wiki/Q371199","display_name":"Cross-site scripting","level":5,"score":0.6825156211853027},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.66512131690979},{"id":"https://openalex.org/C59241245","wikidata":"https://www.wikidata.org/wiki/Q4781497","display_name":"Web application security","level":4,"score":0.576016366481781},{"id":"https://openalex.org/C2779182362","wikidata":"https://www.wikidata.org/wiki/Q17126187","display_name":"Session (web analytics)","level":2,"score":0.5518978238105774},{"id":"https://openalex.org/C35578498","wikidata":"https://www.wikidata.org/wiki/Q193424","display_name":"Web service","level":2,"score":0.5153655409812927},{"id":"https://openalex.org/C148176105","wikidata":"https://www.wikidata.org/wiki/Q206494","display_name":"Transport Layer Security","level":3,"score":0.5083231329917908},{"id":"https://openalex.org/C135910124","wikidata":"https://www.wikidata.org/wiki/Q263718","display_name":"WS-Addressing","level":5,"score":0.4817247688770294},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.4425835609436035},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.4136383533477783},{"id":"https://openalex.org/C79373723","wikidata":"https://www.wikidata.org/wiki/Q386275","display_name":"Web development","level":3,"score":0.17714667320251465},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.1419476568698883},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.08949679136276245}],"mesh":[],"locations_count":7,"locations":[{"id":"doi:10.1145/1237500.1237504","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1237500.1237504","pdf_url":null,"source":{"id":"https://openalex.org/S2642811","display_name":"ACM Transactions on Information and System Security","issn_l":"1094-9224","issn":["1094-9224","1557-7406"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Information and System Security","raw_type":"journal-article"},{"id":"pmh:oai:ris.utwente.nl:openaire_cris_publications/8441c6ac-9908-4428-ba21-d177e71bb18e","is_oa":false,"landing_page_url":"https://research.utwente.nl/en/publications/8441c6ac-9908-4428-ba21-d177e71bb18e","pdf_url":null,"source":{"id":"https://openalex.org/S4406922991","display_name":"University of Twente Research Information","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Bhargavan, K, Corin, R, Fournet, C & Gordon, A D 2007, 'Secure Sessions for Web Services', ACM transactions on information and system security, vol. 10, no. 2, 8. https://doi.org/10.1145/1237500.1237504","raw_type":"info:eu-repo/semantics/publishedVersion"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.100.5984","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.100.5984","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://www.msr-inria.inria.fr/~corin/pubs/bha07.pdf","raw_type":"text"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.133.4521","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.133.4521","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://research.microsoft.com/users/fournet/papers/secure-sessions-for-web-services-sws.pdf","raw_type":"text"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.150.4259","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.150.4259","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://research.microsoft.com/~adg/Publications/secure-sessions-sws.pdf","raw_type":"text"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.93.9441","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.93.9441","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://research.microsoft.com/users/fournet/papers/secure-sessions-for-web-services-tissec-draft.pdf","raw_type":"text"},{"id":"pmh:oai:ris.utwente.nl:publications/c47d4feb-ad14-4158-a77c-65679dd2c90b","is_oa":false,"landing_page_url":"http://research.microsoft.com/projects/samoa/secure-sessions-with-scripts.pdf","pdf_url":null,"source":{"id":"https://openalex.org/S4406922991","display_name":"University of Twente Research Information","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":""}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.5899999737739563,"id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":49,"referenced_works":["https://openalex.org/W58444130","https://openalex.org/W184620699","https://openalex.org/W1484172663","https://openalex.org/W1545426036","https://openalex.org/W1557600385","https://openalex.org/W1562901937","https://openalex.org/W1588668163","https://openalex.org/W1589312904","https://openalex.org/W1603799276","https://openalex.org/W1949661937","https://openalex.org/W1973054120","https://openalex.org/W1982325601","https://openalex.org/W1990431387","https://openalex.org/W1994676271","https://openalex.org/W1996736473","https://openalex.org/W2029693536","https://openalex.org/W2074244772","https://openalex.org/W2104130981","https://openalex.org/W2104655005","https://openalex.org/W2108978217","https://openalex.org/W2114189125","https://openalex.org/W2117064875","https://openalex.org/W2117514386","https://openalex.org/W2118870447","https://openalex.org/W2119617924","https://openalex.org/W2121262961","https://openalex.org/W2121634453","https://openalex.org/W2121990267","https://openalex.org/W2125515762","https://openalex.org/W2125634737","https://openalex.org/W2127035198","https://openalex.org/W2128435514","https://openalex.org/W2131660291","https://openalex.org/W2133556935","https://openalex.org/W2145415641","https://openalex.org/W2146973388","https://openalex.org/W2151353792","https://openalex.org/W2156186849","https://openalex.org/W2156773905","https://openalex.org/W2175661655","https://openalex.org/W2276605304","https://openalex.org/W2413236481","https://openalex.org/W2465326068","https://openalex.org/W3013607954","https://openalex.org/W3085464677","https://openalex.org/W3125672686","https://openalex.org/W3148554005","https://openalex.org/W3162919972","https://openalex.org/W6636047891"],"related_works":["https://openalex.org/W2421583993","https://openalex.org/W2370639870","https://openalex.org/W2368260703","https://openalex.org/W2360211927","https://openalex.org/W2366216657","https://openalex.org/W2387117606","https://openalex.org/W2381255057","https://openalex.org/W2355963583","https://openalex.org/W2395715019","https://openalex.org/W2358161993"],"abstract_inverted_index":{"We":[0,97,122,137],"address":[1],"the":[2,53,102],"problem":[3],"of":[4,7,55,105,145],"securing":[5],"sequences":[6],"SOAP":[8,25],"messages":[9],"exchanged":[10],"between":[11,85],"web":[12,34],"services":[13],"and":[14,95,107,130,143],"their":[15,133],"clients.":[16],"The":[17],"WS-Security":[18,38],"standard":[19],"defines":[20,74],"basic":[21],"mechanisms":[22,104,129],"to":[23,51,82],"secure":[24,52,83],"traffic,":[26],"one":[27],"message":[28,42],"at":[29],"a":[30,56,99,111,115],"time.":[31],"For":[32],"typical":[33,124],"services,":[35],"however,":[36],"using":[37],"independently":[39],"for":[40,101,113,119],"each":[41,62],"is":[43,48],"rather":[44],"inefficient;":[45],"moreover,":[46],"it":[47],"often":[49],"important":[50],"integrity":[54],"whole":[57],"session,":[58],"as":[59,61,110],"well":[60],"message.":[63],"To":[64],"these":[65,128,146],"ends,":[66],"recent":[67],"specifications":[68],"provide":[69],"further":[70],"SOAP-level":[71],"mechanisms.":[72],"WS-SecureConversation":[73],"security":[75,91,120,135],"contexts":[76,92],",":[77],"which":[78],"can":[79],"be":[80],"used":[81],"sessions":[84],"two":[86],"parties.":[87],"WS-Trust":[88,106],"specifies":[89],"how":[90],"are":[93],"issued":[94],"obtained.":[96],"develop":[98],"semantics":[100],"main":[103,134],"WS-SecureConversation,":[108],"expressed":[109],"library":[112],"TulaFale,":[114],"formal":[116],"scripting":[117],"language":[118],"protocols.":[121],"model":[123],"protocols":[125],"relying":[126],"on":[127],"automatically":[131],"prove":[132],"properties.":[136],"also":[138],"informally":[139],"discuss":[140],"some":[141],"pitfalls":[142],"limitations":[144],"specifications.":[147]},"counts_by_year":[{"year":2019,"cited_by_count":1},{"year":2018,"cited_by_count":1},{"year":2016,"cited_by_count":1},{"year":2015,"cited_by_count":2},{"year":2014,"cited_by_count":2},{"year":2013,"cited_by_count":4},{"year":2012,"cited_by_count":4}],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2025-10-10T00:00:00"}
