This document discusses security architectures for service oriented systems. It introduces the concept of a Service Oriented Security (SOS) architecture, which provides a framework of multiple views to reason about security in a holistic way. The key views discussed are:
- Identity view, which deals with authentication, identity federation, and auditing of identity-related events
- Service view, which focuses on securing individual services and application servers
- Message view, which aims to protect message payloads as they traverse multiple systems
- Deployment view, which analyzes security across the traditional defense in depth layers of physical, network, host, application, and data security
- Transaction view, which models security-related use cases and behaviors across