DocumentCode :
127614
Title :
Service Security Revisited
Author :
Gorski, Peter Leo ; Iacono, Luigi Lo ; Hoai Viet Nguyen ; Torkian, Daniel Behnam
Author_Institution :
Cologne Univ. of Appl. Sci., Cologne, Germany
fYear :
2014
fDate :
June 27 2014-July 2 2014
Firstpage :
464
Lastpage :
471
Abstract :
Developing contemporary software architectures requires the consideration and adoption of the Service-oriented Architecture (SOA) principles. Distributed applications are a very common domain in which SOA guides design decisions in particular. For a long time, SOAP and its related stack of standards have been the only technological choice for implementing SOA-based systems. With the increased adoption of the REST concept, an alternative to SOAP is gaining traction. Security considerations have been part of the SOAP-based standardization work since the very beginning. As a result, a mature and comprehensive set of security-related standards is available for building SOAP-based service systems. REST-ful service systems, however, cannot take advantage of such a fully developed security framework yet. This paper therefore revisits the SOAP-based web services security stack in order to identify commonalities, differences and gaps in the security available for REST-ful services. From these findings a desired REST-ful web services security stack is proposed together with related research, development and standardization challenges.
Keywords :
Web services; security of data; service-oriented architecture; REST-ful Web services security stack; SOA principles; SOAP-based Web services security stack; service security; service-oriented architecture; Encryption; Simple object access protocol; Standards; XML; REST; SOA; SOAP; Security; Services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Services Computing (SCC), 2014 IEEE International Conference on
Conference_Location :
Anchorage, AK
Print_ISBN :
978-1-4799-5065-2
Type :
conf
DOI :
10.1109/SCC.2014.68
Filename :
6930568
Link To Document :
بازگشت