DocumentCode
127614
Title
Service Security Revisited
Author
Gorski, Peter Leo ; Iacono, Luigi Lo ; Hoai Viet Nguyen ; Torkian, Daniel Behnam
Author_Institution
Cologne Univ. of Appl. Sci., Cologne, Germany
fYear
2014
fDate
June 27 2014-July 2 2014
Firstpage
464
Lastpage
471
Abstract
Developing contemporary software architectures requires the consideration and adoption of the Service-oriented Architecture (SOA) principles. Distributed applications are a very common domain in which SOA guides design decisions in particular. For a long time, SOAP and its related stack of standards have been the only technological choice for implementing SOA-based systems. With the increased adoption of the REST concept, an alternative to SOAP is gaining traction. Security considerations have been part of the SOAP-based standardization work since the very beginning. As a result, a mature and comprehensive set of security-related standards is available for building SOAP-based service systems. REST-ful service systems, however, cannot take advantage of such a fully developed security framework yet. This paper therefore revisits the SOAP-based web services security stack in order to identify commonalities, differences and gaps in the security available for REST-ful services. From these findings a desired REST-ful web services security stack is proposed together with related research, development and standardization challenges.
Keywords
Web services; security of data; service-oriented architecture; REST-ful Web services security stack; SOA principles; SOAP-based Web services security stack; service security; service-oriented architecture; Encryption; Simple object access protocol; Standards; XML; REST; SOA; SOAP; Security; Services;
fLanguage
English
Publisher
ieee
Conference_Titel
Services Computing (SCC), 2014 IEEE International Conference on
Conference_Location
Anchorage, AK
Print_ISBN
978-1-4799-5065-2
Type
conf
DOI
10.1109/SCC.2014.68
Filename
6930568
Link To Document