首页> 外文期刊>Future Internet >On the Need for a General REST-Security Framework
【24h】

On the Need for a General REST-Security Framework

机译:需要通用的REST安全框架

获取原文
       

摘要

Contemporary software is inherently distributed. The principles guiding the design of such software have been mainly manifested by the service-oriented architecture (SOA) concept. In a SOA, applications are orchestrated by software services generally operated by distinct entities. Due to the latter fact, service security has been of importance in such systems ever since. A dominant protocol for implementing SOA-based systems is SOAP, which comes with a well-elaborated security framework. As an alternative to SOAP, the architectural style representational state transfer (REST) is gaining traction as a simple, lightweight and flexible guideline for designing distributed service systems that scale at large. This paper starts by introducing the basic constraints representing REST. Based on these foundations, the focus is afterwards drawn on the security needs of REST-based service systems. The limitations of transport-oriented protection means are emphasized and the demand for specific message-oriented safeguards is assessed. The paper then reviews the current activities in respect to REST-security and finds that the available schemes are mostly HTTP-centered and very heterogeneous. More importantly, all of the analyzed schemes contain vulnerabilities. The paper contributes a methodology on how to establish REST-security as a general security framework for protecting REST-based service systems of any kind by consistent and comprehensive protection means. First adoptions of the introduced approach are presented in relation to REST message authentication with instantiations for REST-ful HTTP (web/cloud services) and REST-ful constraint application protocol (CoAP) (internet of things (IoT) services).
机译:现代软件是固有分布的。指导此类软件设计的原则主要由面向服务的体系结构(SOA)概念体现。在SOA中,应用程序通常由不同实体运营的软件服务编排。由于后一个事实,从那时起,服务安全性在此类系统中就变得十分重要。 SOAP是实现基于SOA的系统的主要协议,它带有精心设计的安全框架。作为SOAP的替代方法,体系结构样式表示状态转移(REST)作为设计大规模扩展的分布式服务系统的简单,轻量级和灵活的准则而受到关注。本文首先介绍代表REST的基本约束。基于这些基础,之后将重点放在基于REST的服务系统的安全需求上。强调了以运输为导向的保护手段的局限性,并评估了对特定的以信息为导向的保障措施的需求。然后,本文回顾了有关REST安全性的当前活动,并发现可用的方案主要是基于HTTP的并且非常异构。更重要的是,所有分析的方案都包含漏洞。本文为如何建立REST安全性作为一种通用安全框架提供了一种方法,以通过一致而全面的保护手段来保护任何类型的REST服务系统。引入的方法的首次采用与REST消息身份验证有关,该消息具有REST-ful HTTP(Web /云服务)和REST-ful约束应用协议(CoAP)(物联网(IoT)服务)的实例化。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号