Applying Security for RESTful Web Services – Limitations and Delimitations
نویسندگان
چکیده
The Service Oriented Architecture (SOA) becomes an essential element of modern Enterprise Application Integration (EAI). Among the available SOA implementations, Web Services are most preferable choice by the enterprises as they operate on simple Internet protocols. In principle, web services use SOAP protocol as a base for transmitting requests and responses in between service requester and service provider. In recent years, another kind of web services, RESTful web services, are emerging that is even simpler as it uses normal HTTP methods and URIs. Many security solutions for SOAP web services are already exists in market as products and standards; and also many researches are still going on. The RESTful web service is not a standard and it does not contain any security components within it. Research scholars and product based corporations are providing security recommendations for RESTful web services. However, there is no standard security solution defined as of now. And also applying security for RESTful web services is not a straight forward approach; there are few limitations and delimitations that we should consider in developing a security solution for RESTful web services. This paper analyses those limitations and delimitations with the authors’ practical implementation experience of applying security to RESTful web services. Keywords— RESTful Web Services, Security, Secure Web
منابع مشابه
A Novel Approach to Implement Message Level Security in RESTful Web Services
The world is rapidly adopting RESTful web services for most of its tasks. The once popular SOAP-based web services are fast losing ground owing to this. RESTful web services are light weight services without strict message formats. RESTful web services, unlike SOAP, are capable of message transfer in any format be it XML, JSON, plain-text. However, in spite of these positives, ensuring message ...
متن کاملSupporting the Creation of Semantic RESTful Service Descriptions
Research on semantic Web services (SWS) has been devoted to reduce the extensive manual effort required for manipulating Web services by enhancing them with semantic information. Recently, the world around services on the Web, thus far limited to “classical” Web services based on SOAP and WSDL, has significantly evolved with the proliferation of Web applications and APIs, often referred to as R...
متن کاملAn architecture based on SOA, RESTful and Mashup for C2 mobile applications
The development of service-oriented architectures for C2 systems in mobile applications has major challenges for security and availability of services. The construction of secure services causes an increase in the bandwidth required for the service to be provided and impacts the way those services are made. This study aims to present an alternative for mobile agents be able to consume RESTful s...
متن کاملRESTful Security
We take a look into the REST architectural style of making scalable web applications and find out the critical requirements that mismatch with the current web security and privacy architecture. One of the core challenges is the inability of the web security model to scale up with caching when millions of users share confidential data inside communities. Our contribution includes a new solution ...
متن کاملFault-tolerant timestamp-based two-phase commit protocol for RESTful services
Service-oriented architecture provides interoperability and weak coupling features for software development. Representational state transfer (REST) is an architectural style that has attracted attention in the SOA domain as it allows the development of Web services based on original principles of the World Wide Web. Unlike Web service specifications, which are based on Simple Object Access Prot...
متن کامل