...frameworks that enforce policies, and remove security logic from application code. WS-Security is only good at the web servicetier. In N-tier systems users are authenticated at the client, ultimately determining access to data stores. The challenge...
http://soa.sys-con.com/node/981844