Inicio  /  Future Internet  /  Vol: 11 Par: 3 (2019)  /  Artículo
ARTÍCULO
TITULO

On the Need for a General REST-Security Framework

Luigi Lo Iacono    
Hoai Viet Nguyen and Peter Leo Gorski    

Resumen

Contemporary software is inherently distributed. The principles guiding the design of such software have been mainly manifested by the service-oriented architecture (SOA) concept. In a SOA, applications are orchestrated by software services generally operated by distinct entities. Due to the latter fact, service security has been of importance in such systems ever since. A dominant protocol for implementing SOA-based systems is SOAP, which comes with a well-elaborated security framework. As an alternative to SOAP, the architectural style representational state transfer (REST) is gaining traction as a simple, lightweight and flexible guideline for designing distributed service systems that scale at large. This paper starts by introducing the basic constraints representing REST. Based on these foundations, the focus is afterwards drawn on the security needs of REST-based service systems. The limitations of transport-oriented protection means are emphasized and the demand for specific message-oriented safeguards is assessed. The paper then reviews the current activities in respect to REST-security and finds that the available schemes are mostly HTTP-centered and very heterogeneous. More importantly, all of the analyzed schemes contain vulnerabilities. The paper contributes a methodology on how to establish REST-security as a general security framework for protecting REST-based service systems of any kind by consistent and comprehensive protection means. First adoptions of the introduced approach are presented in relation to REST message authentication with instantiations for REST-ful HTTP (web/cloud services) and REST-ful constraint application protocol (CoAP) (internet of things (IoT) services).

Palabras claves

 Artículos similares

       
 
Vardan Asatryan, Tigran Vardanyan, Nelli Barseghyan, Marine Dallakyan and Bardukh Gabrielyan    
The endangered endemic species Sevan trout (Salmo ischchan Kessler, 1877) is under the threat of extinction and its survival is dependent on restocking by smolts. Thus, there is an urgent need to find an effective solution for restocking wild populations... ver más
Revista: Water

 
Viriya Taecharungroj    
In this study, the author collected tweets about ChatGPT, an innovative AI chatbot, in the first month after its launch. A total of 233,914 English tweets were analyzed using the latent Dirichlet allocation (LDA) topic modeling algorithm to answer the qu... ver más

 
Jiaming Ye, Defu Che, Baodong Ma, Quan Liu, Kehan Qiu and Xiangxiang Shang    
Existing approaches for the 3D modeling of tunnels suffer from several problems, such as highly difficult data acquisition, redundancy of model data, large computational burden, and the inability of the resulting models to be monolithic. Therefore, solut... ver más

 
Hyowon Ban and Hye-jin Kim    
This research is a pilot study to develop a maritime traffic control system that supports the decision-making process of control officers, and to evaluate the usability of a prototype tool developed in this study. The study analyzed the movements of mult... ver más

 
Shaojun Liu, Xiawei Chen, Fengji Zhang, Yiyan Liu and Junlian Ge    
With the rapid pace of urbanization, enhancing the quality of life has become an urgent demand for the general public in both developed and developing countries. This study addresses the pressing need to understand the spatial distribution and underlying... ver más