Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

On Design of Secure APIs for IoT Applications – Using Taiwan Uniform e-Invoices as Examples

View through CrossRef
Defining standard application programming interfaces (APIs) plays an important role in Internet of Things (IoT) applications to achieve interpretability. Among different issues of designing APIs for IoT applications, this study focuses on the security issue of designing an API for people to access data about machines, sensors, and other objects collected in servers. To address the issue, this study shares the experiences of designing APIs for Taiwan uniform e-invoices. To prevent tax evasion, Taiwan government holds uniform invoice lottery every two months. Because invoice owners may win NT $10,000,000, the security of APIs to access e-invoices is critical. This study illustrates the security considerations in designing major APIs of Taiwan uniform e-invoices. In addition to common security issues, such as communication security, authentication, and non-repudiation, the APIs consider special security issues in different scenarios. The API for point of sales (POS) applications and ERP systems addresses the security consideration to transfer bulk data among machines; the e-invoice donation API proposes a scheme to restrict that each authorized person can only invoke the API through a specific device; the API for mobile applications considers the issue that misused mobile applications may transfer personal sensitive data and credentials to others secretly; the API for invoice exchanging allows people to obtain e-invoices immediately after transactions with their smart phones and to verify the integrity of the invoices. While this study gives examples of designing secure API for IoT applications from different perspectives, the paper can hopefully contribute to the security of IoT applications.
Title: On Design of Secure APIs for IoT Applications – Using Taiwan Uniform e-Invoices as Examples
Description:
Defining standard application programming interfaces (APIs) plays an important role in Internet of Things (IoT) applications to achieve interpretability.
Among different issues of designing APIs for IoT applications, this study focuses on the security issue of designing an API for people to access data about machines, sensors, and other objects collected in servers.
To address the issue, this study shares the experiences of designing APIs for Taiwan uniform e-invoices.
To prevent tax evasion, Taiwan government holds uniform invoice lottery every two months.
Because invoice owners may win NT $10,000,000, the security of APIs to access e-invoices is critical.
This study illustrates the security considerations in designing major APIs of Taiwan uniform e-invoices.
In addition to common security issues, such as communication security, authentication, and non-repudiation, the APIs consider special security issues in different scenarios.
The API for point of sales (POS) applications and ERP systems addresses the security consideration to transfer bulk data among machines; the e-invoice donation API proposes a scheme to restrict that each authorized person can only invoke the API through a specific device; the API for mobile applications considers the issue that misused mobile applications may transfer personal sensitive data and credentials to others secretly; the API for invoice exchanging allows people to obtain e-invoices immediately after transactions with their smart phones and to verify the integrity of the invoices.
While this study gives examples of designing secure API for IoT applications from different perspectives, the paper can hopefully contribute to the security of IoT applications.

Related Results

L᾽«unilinguisme» officiel de Constantinople byzantine (VIIe-XIIe s.)
L᾽«unilinguisme» officiel de Constantinople byzantine (VIIe-XIIe s.)
&nbsp; <p>&Nu;ί&kappa;&omicron;&sigmaf; &Omicron;&iota;&kappa;&omicron;&nu;&omicron;&mu;ί&delta;&eta;&sigmaf;</...
Cometary Physics Laboratory: spectrophotometric experiments
Cometary Physics Laboratory: spectrophotometric experiments
&lt;p&gt;&lt;strong&gt;&lt;span dir=&quot;ltr&quot; role=&quot;presentation&quot;&gt;1. Introduction&lt;/span&gt;&lt;/strong&...
North Syrian Mortaria and Other Late Roman Personal and Utility Objects Bearing Inscriptions of Good Luck
North Syrian Mortaria and Other Late Roman Personal and Utility Objects Bearing Inscriptions of Good Luck
<span style="font-size: 11pt; color: black; font-family: 'Times New Roman','serif'">&Pi;&Eta;&Lambda;&Iota;&Nu;&Alpha; &Iota;&Gamma;&Delta...
Morphometry of an hexagonal pit crater in Pavonis Mons, Mars
Morphometry of an hexagonal pit crater in Pavonis Mons, Mars
&lt;p&gt;&lt;strong&gt;Introduction:&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Pit craters are peculiar depressions found in almost every terrestria...
Un manoscritto equivocato del copista santo Theophilos († 1548)
Un manoscritto equivocato del copista santo Theophilos († 1548)
<p><font size="3"><span class="A1"><span style="font-family: 'Times New Roman','serif'">&Epsilon;&Nu;&Alpha; &Lambda;&Alpha;&Nu;&...
Ballistic landslides on comet 67P/Churyumov&#8211;Gerasimenko
Ballistic landslides on comet 67P/Churyumov&#8211;Gerasimenko
&lt;p&gt;&lt;strong&gt;Introduction:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The slow ejecta (i.e., with velocity lower than escape velocity) and l...
Effects of a new land surface parametrization scheme on thermal extremes in a Regional Climate Model
Effects of a new land surface parametrization scheme on thermal extremes in a Regional Climate Model
&lt;p&gt;&lt;span&gt;The &lt;/span&gt;&lt;span&gt;EFRE project Big Data@Geo aims at providing high resolution &lt;/span&gt;&lt;span&...

Back to Top