Inicio  /  Future Internet  /  Vol: 11 Par: 3 (2019)  /  Artículo
ARTÍCULO
TITULO

On the Need for a General REST-Security Framework

Luigi Lo Iacono    
Hoai Viet Nguyen and Peter Leo Gorski    

Resumen

Contemporary software is inherently distributed. The principles guiding the design of such software have been mainly manifested by the service-oriented architecture (SOA) concept. In a SOA, applications are orchestrated by software services generally operated by distinct entities. Due to the latter fact, service security has been of importance in such systems ever since. A dominant protocol for implementing SOA-based systems is SOAP, which comes with a well-elaborated security framework. As an alternative to SOAP, the architectural style representational state transfer (REST) is gaining traction as a simple, lightweight and flexible guideline for designing distributed service systems that scale at large. This paper starts by introducing the basic constraints representing REST. Based on these foundations, the focus is afterwards drawn on the security needs of REST-based service systems. The limitations of transport-oriented protection means are emphasized and the demand for specific message-oriented safeguards is assessed. The paper then reviews the current activities in respect to REST-security and finds that the available schemes are mostly HTTP-centered and very heterogeneous. More importantly, all of the analyzed schemes contain vulnerabilities. The paper contributes a methodology on how to establish REST-security as a general security framework for protecting REST-based service systems of any kind by consistent and comprehensive protection means. First adoptions of the introduced approach are presented in relation to REST message authentication with instantiations for REST-ful HTTP (web/cloud services) and REST-ful constraint application protocol (CoAP) (internet of things (IoT) services).

Palabras claves

 Artículos similares

       
 
Vardan Asatryan, Tigran Vardanyan, Nelli Barseghyan, Marine Dallakyan and Bardukh Gabrielyan    
The endangered endemic species Sevan trout (Salmo ischchan Kessler, 1877) is under the threat of extinction and its survival is dependent on restocking by smolts. Thus, there is an urgent need to find an effective solution for restocking wild populations... ver más
Revista: Water

 
Yang Chen, Kexin Liu, Sijun Jiang, Yiqun Sun and Hui Chen    
The system differential response method for inverse estimation has received much attention in the hydrology literature. However, its underlying mechanisms remain largely unexplored, highlighting the need for this study. This study proposes the relation d... ver más
Revista: Water

 
Mao Nishira, Satoshi Ito, Hiroki Nishikawa, Xiangbo Kong and Hiroyuki Tomiyama    
Delivery drones have been attracting attention as a means of solving recent logistics issues, and many companies are focusing on their practical applications. Many research studies on delivery drones have been active for several decades. Among them, exte... ver más
Revista: Drones

 
Alvaro Verdu-Candela, Carmen Femenia-Ribera, Gaspar Mora-Navarro and Rafael Sierra-Requena    
It is widely accepted that old cadastral maps have multiple uses, such as reestablishing cadastral parcel boundaries, municipality boundaries, and coastal limits, or conducting historical, economic, and social studies. In Spain, the Directorate General f... ver más

 
Chima Ibeanu, Mazyar Ghadiri Nejad and Matina Ghasemi    
Emphasizing the need to provide a coordinated flood management strategy in the country and avoid acting in an isolated way when it occurs, improving the attitude of flood control during floods, and controlling floods with comprehensive analysis are among... ver más
Revista: Urban Science