Enabling message security for RESTful services

Serme, Gabriel; De Oliveira, Anderson Santana; Massiera, Julien, Roudier, Yves
ICWS 2012, 19th IEEE International Conference on Web Services, June 24-29, 2012, Honolulu, Hawaii, USA

The security and dependability of cloud applications require strong confidence in the communication protocol used to access web resources. The mainstream service providers

nowadays are shifting to REST-based services in the detriment of SOAP-based ones. REST proposes a lightweight approach to consume resources with no specific encapsulation, thus

lacking of meta-data descriptions for security requirements. Currently, the security of RESTful services relies on ad-hoc security mechanisms (whose implementation is error-prone) or on the transport layer security (offering poor flexibility). We introduce the REST security protocol to provide secure service communication, together with its performance analysis when compared to equivalent WS-Security configuration.


DOI
Type:
Conférence
City:
Honolulu
Date:
2012-06-24
Department:
Sécurité numérique
Eurecom Ref:
3739
Copyright:
© 2012 IEEE. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE.
See also:

PERMALINK : https://www.eurecom.fr/publication/3739