• DocumentCode
    127614
  • Title

    Service Security Revisited

  • Author

    Gorski, Peter Leo ; Iacono, Luigi Lo ; Hoai Viet Nguyen ; Torkian, Daniel Behnam

  • Author_Institution
    Cologne Univ. of Appl. Sci., Cologne, Germany
  • fYear
    2014
  • fDate
    June 27 2014-July 2 2014
  • Firstpage
    464
  • Lastpage
    471
  • Abstract
    Developing contemporary software architectures requires the consideration and adoption of the Service-oriented Architecture (SOA) principles. Distributed applications are a very common domain in which SOA guides design decisions in particular. For a long time, SOAP and its related stack of standards have been the only technological choice for implementing SOA-based systems. With the increased adoption of the REST concept, an alternative to SOAP is gaining traction. Security considerations have been part of the SOAP-based standardization work since the very beginning. As a result, a mature and comprehensive set of security-related standards is available for building SOAP-based service systems. REST-ful service systems, however, cannot take advantage of such a fully developed security framework yet. This paper therefore revisits the SOAP-based web services security stack in order to identify commonalities, differences and gaps in the security available for REST-ful services. From these findings a desired REST-ful web services security stack is proposed together with related research, development and standardization challenges.
  • Keywords
    Web services; security of data; service-oriented architecture; REST-ful Web services security stack; SOA principles; SOAP-based Web services security stack; service security; service-oriented architecture; Encryption; Simple object access protocol; Standards; XML; REST; SOA; SOAP; Security; Services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Services Computing (SCC), 2014 IEEE International Conference on
  • Conference_Location
    Anchorage, AK
  • Print_ISBN
    978-1-4799-5065-2
  • Type

    conf

  • DOI
    10.1109/SCC.2014.68
  • Filename
    6930568