首页> 外文会议>International conference on trust, privacy and security in digital business >On the Security Expressiveness of REST-Based API Definition Languages
【24h】

On the Security Expressiveness of REST-Based API Definition Languages

机译:基于REST的API定义语言的安全性

获取原文

摘要

Modern software is inherently distributed. Applications are decomposed into functional components of which most are provided by third parties usually deployed as software services scattered around the network. Available services can be discovered and orchestrated by service consumers in a flexible and on-the-fly manner. To do so, a standardized specification of the service's functionalities is required. Apart from functional aspects, such an interface definition language needs to offer expressions for specifying important non-functional facets in addition, such as security. With WSDL and WS-Security such a standardized service description language and a mature security framework are available for the SOAP domain. For REST-based web services such standards are, however, missing. To overcome these shortcomings, many distinct sources propose service description languages and security schemes for REST-based web services. This paper provides a systematic analysis of these languages with a specific focus on their ability to express security policies. The obtained results reveal substantial limitations in all analyzed specification languages.
机译:现代软件本质上分发。应用程序被分解为功能组件,其中大多数由通常部署为遍布网络的软件服务的第三方提供。可以通过灵活且可行的方式发现可用的服务和由服务消费者进行策划。为此,需要提供服务的功能的标准化规范。除了功能方面,这种接口定义语言需要提供表达式,以便另外还提供指定重要的非功能方面的表达式,例如安全性。使用WSDL和WS-Security此类标准化服务描述语言和成熟安全框架可用于SOAP域。对于基于REST的Web服务,此类标准缺失。为了克服这些缺点,许多不同的来源提出了基于REST的Web服务的服务描述语言和安全方案。本文提供了对这些语言的系统分析,并特别关注他们表达安全策略的能力。所获得的结果揭示了所有分析的规范语言中的大量限制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号