首页> 外文会议>International Conference on Trust, Privacy and Security in Digital Business >On the Security Expressiveness of REST-Based API Definition Languages
【24h】

On the Security Expressiveness of REST-Based API Definition Languages

机译:基于REST的API定义语言的安全性表达式

获取原文

摘要

Modern software is inherently distributed. Applications are decomposed into functional components of which most are provided by third parties usually deployed as software services scattered around the network. Available services can be discovered and orchestrated by service consumers in a flexible and on-the-fly manner. To do so, a standardized specification of the service's functionalities is required. Apart from functional aspects, such an interface definition language needs to offer expressions for specifying important non-functional facets in addition, such as security. With WSDL and WS-Security such a standardized service description language and a mature security framework are available for the SOAP domain. For REST-based web services such standards are, however, missing. To overcome these shortcomings, many distinct sources propose service description languages and security schemes for REST-based web services. This paper provides a systematic analysis of these languages with a specific focus on their ability to express security policies. The obtained results reveal substantial limitations in all analyzed specification languages.
机译:现代软件本质上是分布式的。应用程序被分解成其中大部分是由通常部署为软件服务分散各地的网络第三方提供的功能组件。提供的服务可以被发现,并以灵活和即时的方式通过服务消费者打造。要做到这一点,则需要该服务的功能性的标准化规范。除了功能方面,这样的接口定义语言需要提供表达式,用于指定另外重要的非功能性方面,如安全性。随着WSDL和WS-Security这样的标准化服务描述语言和成熟的安全框架,可用于SOAP域。对于基于REST的Web服务这样的标准,但缺。为了克服这些缺点,许多不同的信号源提出服务描述语言和安全方案基于REST的Web服务。本文提供这些语言并特别关注他们的表达能力安全策略的系统的分析。得到的结果显示在所有的分析说明语言很大的限制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号