Network Working Group G. Bossert
Request for Comments: 2084 S. Cooper
Category: Informational Silicon Graphics Inc.
W. Drummond
IEEE, Inc.
January 1997
Considerations for Web Transaction Security
1. Introduction
The use of the HyperText Transport Protocol [1] to provide specialized or commercial services and personal or private data necessitates the development of secure versions that include privacy and authentication services. Such services may be provided as extensions to HTTP, or as encapsulating security protocols; for the purposes of this document, all such enhancements will be referred to as WTS.
Bossert, et. al. Informational [Page 1]
RFC 2084 Considerations for Web Transaction Security January 1997 1.1 TerminologyThis following terms have specific meaning in the context of this document. The HTTP specification [1] defines additional useful terms.
2. General Requirements
WTS must define the following services. These services must be provided independently of each other and support the needs of proxies and intermediaries
3. Confidentiality
WTS must be able to provide confidentiality for both requests and responses. Note: because the identity of the object being requested is potentially sensitive, the URI of the request should be confidential; this is particularly critical in the common case of form data or other user input being passed in the URI.
Bossert, et. al. Informational [Page 2]
RFC 2084 Considerations for Web Transaction Security January 1997 4. Service AuthenticationWTS should support the authentication of gatewayed services to the client.
5. User Authentication
WTS must support the authentication of the client to the server.
6. Integrity
WTS must provide assurance of the integrity of the HTTP transaction, including the HTTP headers and data objects of both client requests and server responses.
7. Integration
In order to support integration with current and future versions of HTTP, and to provide extendibility and independence of development, the secure services provided by WTS must be orthogonal to and independent of other services provided by HTTP. In accordance with the layered model of network protocols, WTS must be:
Bossert, et. al. Informational [Page 3]
RFC 2084 Considerations for Web Transaction Security January 1997
o independent of the content or nature of data objects being transported although special attention to reference integrity of hyperlinked objects may be appropriate
8. Multiple Mechanisms
WTS must be compatible with multiple mechanisms for authentication and encryption. Support for multiple mechanisms is required for a number of reasons:
Bossert, et. al. Informational [Page 4]
RFC 2084 Considerations for Web Transaction Security January 1997
References
Bossert, et. al. Informational [Page 5]
RFC 2084 Considerations for Web Transaction Security January 1997
Authors' Addresses