Enterprise API Security and GDPR Compliance: Design and Implementation Perspective

被引:12
|
作者
Hussain, Fatima [1 ]
Hussain, Rasheed [2 ]
Noye, Brett [3 ]
Sharieh, Salah [3 ]
机构
[1] Royal Bank Canada, RBC, API Secur & Governance Squad, Toronto, ON, Canada
[2] Innopolis Univ, Innopolis, Russia
[3] Royal Bank Canada, Toronto, ON, Canada
关键词
General Data Protection Regulation; Logic gates; Authorization; Enterprise resource planning; Authentication;
D O I
10.1109/MITP.2020.2973852
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the advancements in enterprise-level business development, the demand for new applications and services is overwhelming. For the development and delivery of such applications and services, enterprise businesses rely on Application Programming Interfaces (APIs). APIs provide interface to enable the communication among different applications. In essence, API is a double-edged sword; on one hand, API helps in expanding the business through sharing value and utility, but on the other hand, it raises security and privacy issues. Since the applications usually use APIs to retrieve important and critical data, it is extremely important to make sure that effective access control and security mechanisms are in place so that the data do not fall into wrong hands. In this context, in this article, we discuss the current state of the enterprise API security and the role of Machine Learning (ML) in an API security. We also discuss the General Data Protection Regulation (GDPR) Compliance and its effect on the API security.
引用
收藏
页码:81 / 89
页数:9
相关论文
共 50 条
  • [41] Enterprise Resource Planning System Implementation: a User Perspective
    Reitsma, Ewout
    Hilletofth, Per
    Mukhtar, Umer
    OPERATIONS AND SUPPLY CHAIN MANAGEMENT-AN INTERNATIONAL JOURNAL, 2018, 11 (03): : 110 - 117
  • [42] Implementation of enterprise resource planning systems: a user perspective
    Reitsma, E.
    Hilletofth, P.
    Mulkhtar, U.
    INTERNATIONAL CONFERENCE ON INDUSTRIAL AND SYSTEMS ENGINEERING (ICONISE) 2017, 2018, 337
  • [43] Design and implementation of an intelligent decision tool for enterprise
    Li, Ming
    Liu, Shengjun
    Cai, Qingsheng
    Xiaoxing Weixing Jisuanji Xitong/Mini-Micro Systems, 2000, 21 (05): : 544 - 546
  • [44] Design and Implementation of Information Management System for Enterprise
    Xin, Dong
    Zhao, Hongxia
    Zhou, Baogang
    PROCEEDINGS OF THE 2015 INTERNATIONAL INDUSTRIAL INFORMATICS AND COMPUTER ENGINEERING CONFERENCE, 2015, : 56 - 60
  • [45] Design and implementation of enterprise marketing management system
    Guo, Li
    AGRO FOOD INDUSTRY HI-TECH, 2017, 28 (01): : 2695 - 2699
  • [46] Enterprise office automation system design and implementation
    Libaier, Di
    2015 SEVENTH INTERNATIONAL CONFERENCE ON MEASURING TECHNOLOGY AND MECHATRONICS AUTOMATION (ICMTMA 2015), 2015, : 457 - 461
  • [47] Service level agreement-based GDPR compliance and security assurance in (multi)Cloud-based systems
    Rios, Erkuden
    Iturbe, Eider
    Larrucea, Xabier
    Rak, Massimiliano
    Mallouli, Wissam
    Dominiak, Jacek
    Muntes, Victor
    Matthews, Peter
    Gonzalez, Luis
    IET SOFTWARE, 2019, 13 (03) : 213 - 222
  • [48] Design and implementation of enterprise spatial data warehouse
    Liang, Yin
    Zhang, Hong
    RESEARCH AND PRACTICAL ISSUES OF ENTERPRISE INFORMATION SYSTEMS II, VOL 1, 2008, 254 : 75 - +
  • [49] Design and Implementation of Manufacturing Enterprise CRM System
    Yu, Yong
    Ma, Chuang
    Wang, Qun
    Zhu, Gen
    2013 3RD INTERNATIONAL CONFERENCE ON SOCIAL SCIENCES AND SOCIETY (ICSSS 2013), PT 12, 2013, 43 : 56 - 60
  • [50] Design and implementation for transport dispatch system in enterprise
    Wang, Feng
    Shi, Ronghua
    THIRD INTERNATIONAL CONFERENCE ON GENETIC AND EVOLUTIONARY COMPUTING, 2009, : 731 - +