IMO, although there are more and more new terms in security, the idea never changes!
Encryption is the only means to perform confidentiality, while digital signature is the most common way for authentication.
The method to carry them out maybe differ, say algorithms used, using RSA or ECC, DSA etc, or using other ways, like XML DS etc, the idea does not change much, just the method changes.
Thus, I will think Web Services security is just a subset of current security measurement, instead of new stuffs. In anytime, Web Services security will still be based on the existing security mechanisms.
Nick
SCJP 1.2, OCP 9i DBA, SCWCD 1.3, SCJP 1.4 (SAI), SCJD 1.4, SCWCD 1.4 (Beta), ICED (IBM 287, IBM 484, IBM 486), SCMAD 1.0 (Beta), SCBCD 1.3, ICSD (IBM 288), ICDBA (IBM 700, IBM 701), SCDJWS, ICSD (IBM 348), OCP 10g DBA (Beta), SCJP 5.0 (Beta), SCJA 1.0 (Beta), MCP(70-270), SCBCD 5.0 (Beta), SCJP 6.0, SCEA for JEE5 (in progress)