loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Marc Hüffmeyer 1 ; Florian Haupt 2 ; Frank Leymann 2 and Ulf Schreier 1

Affiliations: 1 Hochschule Furtwangen, Germany ; 2 University of Stuttgart, Germany

Keyword(s): REST, Web Services, Authorization, Attribute Based Access Control.

Related Ontology Subjects/Areas/Topics: Cloud Computing ; Collaboration and e-Services ; Data Engineering ; e-Business ; Enterprise Information Systems ; Mobile Software and Services ; Ontologies and the Semantic Web ; Services Science ; Software Agents and Internet Computing ; Software Engineering ; Software Engineering Methods and Techniques ; Telecommunications ; Web Services ; Wireless Information Networks and Systems

Abstract: The architectural style named Representational State Transfer (REST) is nowadays widely established and still enjoys a growing popularity. One of the core principles of REST is referred as ”Hypermedia as the Engine of Application State” (HATEOAS). HATEOAS is one of the foundations of the scalability that RESTful systems provide and enables the decoupling of client and server. But the realization of HATEOAS is challenging, because there is no systematic approach how to enforce the constraint. Therefore, the implementation is mostly up to the developer of a RESTful service. This work describes a new method of how to apply the HATEOAS constraint. We describe a method that systematically enables HATEOAS based on REST API models and the integration of access control mechanisms. In order to avoid unauthorized access attempts and unnecessary network traffic, the resource representations are customized to the requesting subject. References that lead to not accessible resources, are not inclu ded in the customized resource representations. Therefore, an attribute based access control mechanism is extended to distinguish between static and dynamic attributes. A 2-phase authorization procedure is introduced that relies on this discrimination and determines the references which must be included in the resource representation. The result is a flexible realization of HATEOAS based on formal models. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 18.227.228.95

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Hüffmeyer, M.; Haupt, F.; Leymann, F. and Schreier, U. (2018). Authorization-aware HATEOAS. In Proceedings of the 8th International Conference on Cloud Computing and Services Science - CLOSER; ISBN 978-989-758-295-0; ISSN 2184-5042, SciTePress, pages 78-89. DOI: 10.5220/0006683700780089

@conference{closer18,
author={Marc Hüffmeyer. and Florian Haupt. and Frank Leymann. and Ulf Schreier.},
title={Authorization-aware HATEOAS},
booktitle={Proceedings of the 8th International Conference on Cloud Computing and Services Science - CLOSER},
year={2018},
pages={78-89},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0006683700780089},
isbn={978-989-758-295-0},
issn={2184-5042},
}

TY - CONF

JO - Proceedings of the 8th International Conference on Cloud Computing and Services Science - CLOSER
TI - Authorization-aware HATEOAS
SN - 978-989-758-295-0
IS - 2184-5042
AU - Hüffmeyer, M.
AU - Haupt, F.
AU - Leymann, F.
AU - Schreier, U.
PY - 2018
SP - 78
EP - 89
DO - 10.5220/0006683700780089
PB - SciTePress