本文基于Web 服务的典型应用的安全需求,将Web 服务安全规范协同使用设计了基 于属性的Web 服务安全访问控制方案,将安全应用于SOAP 消息,为Web 服务安全提供整体的解决方案,既满足端到端的消息安全要求,又提供访问控制。方案充分考虑Web 服务跨组织、动态交互的特点,使用SAML 断言传递安全信息以实现信任传递,针对PKI 部署复杂以及不同PKI 解决方案之间难于互操作的缺点,使用XKMS 服务提供PKI 功能。 关键字: 安全访问;Web 服务;SOAP;访问控制 Abstract: Based on the research of Web security specifications, it put forwards a message level security model for the typical Web Services application. It provides both security transport of SOAP messages and an access control security. 'The model uses XKMS as a replacement of PKI and SAML assertion to exchange authentication as well as authorization information of users. Theimplement of the model depends on a message processing security. Keywords: Security Access; Web Service; SOAP; Access Control