WS-SecureConversation

WS-SecureConversation is a Web Services specification, created by IBM and others, that works in conjunction with WS-Security, WS-Trust and WS-Policy to allow the creation and sharing of security contexts.

[1] WS-SecureConversation is meant to provide an extensible framework and a flexible syntax, with which one could implement various security mechanisms.

Following a pattern similar to TLS, WS-SecureConversation establishes a kind of session key.

The processing overhead for key establishment is reduced significantly when compared to WS-Security in the case of frequent message exchanges.

However, a new layer is put on top of WS-Security, that implies other WS-* protocols like WS-Addressing and WS-Trust.