The search functionality is under construction.

IEICE TRANSACTIONS on Information

A Practical Model Driven Approach for Designing Security Aware RESTful Web APIs Using SOFL

Busalire Onesmus EMEKA, Soichiro HIDAKA, Shaoying LIU

  • Full Text Views

    8

  • Cite this

Summary :

RESTful web APIs have become ubiquitous with most modern web applications embracing the micro-service architecture. A RESTful API provides data over the network using HTTP probably interacting with databases and other services and must preserve its security properties. However, REST is not a protocol but rather a set of guidelines on how to design resources accessed over HTTP endpoints. There are guidelines on how related resources should be structured with hierarchical URIs as well as how the different HTTP verbs should be used to represent well-defined actions on those resources. Whereas security has always been critical in the design of RESTful APIs, there are few or no clear model driven engineering techniques utilizing a secure-by-design approach that interweaves both the functional and security requirements. We therefore propose an approach to specifying APIs functional and security requirements with the practical Structured-Object-oriented Formal Language (SOFL). Our proposed approach provides a generic methodology for designing security aware APIs by utilizing concepts of domain models, domain primitives, Ecore metamodel and SOFL. We also describe a case study to evaluate the effectiveness of our approach and discuss important issues in relation to the practical applicability of our method.

Publication
IEICE TRANSACTIONS on Information Vol.E106-D No.5 pp.986-1000
Publication Date
2023/05/01
Publicized
2023/02/13
Online ISSN
1745-1361
DOI
10.1587/transinf.2022EDP7194
Type of Manuscript
PAPER
Category
Data Engineering, Web Information Systems

Authors

Busalire Onesmus EMEKA
  Hosei University
Soichiro HIDAKA
  Hosei University
Shaoying LIU
  Hiroshima University

Keyword