Open Caching API Security

Working Group:

In Collaboration With:

Project Status:

Working

The project is actively being worked on.

Start:

October 1, 2023

Target End:

June 30, 2025
  • Home
  • Open Caching API Security

Problem Statement

Until now, the Open Caching APIs, and specifically the Simple API, have been with only minimal guidance on how to use them securely, and without incorporating already standardized mechanisms. A proposed OC API Security document aims to address this.

Project Description

Machine-to-machine communication between different systems and roles in an Open Caching architecture requires the use of multiple APIs to facilitate the provisioning of services, the sharing of critical information or content management, and other functions. These activities are typically based on relationships that are associated with contractual agreements and are not publicly available. Thus, Service Level Agreements (SLAs) are applied to ensure the continuous operation of all systems, and only authorized entities have the capability to use the APIs. The document provides guidelines for using a security framework that permits the components of an Open Caching system to interoperate securely and consistently, ensuring that only authenticated and authorized entities can access the OC APIs.

Project Type

Document

Project Leads

Advisors

There are no SMEs associated with this project.

Draft Documents

Estimated Publication Date: Q2 2025

(DRAFT) SVTA2074: Open Caching API Security

Machine-to-machine communication between different systems and roles in an Open Caching architecture requires the use of multiple APIs to facilitate the provisioning of services, the sharing of critical information or content management, and other functions.

These activities are typically based on relationships that are associated with contractual agreements and are not publicly available. Thus, Service Level Agreements (SLAs) are applied to ensure the continuous operation of all systems, and only authorized entities have the capability to use the APIs.

The document provides guidelines for using a security framework that permits the components of an Open Caching system to interoperate securely and consistently, ensuring that only authenticated and authorized entities can access the OC APIs.


Goals and Objectives

  • Completion of the Open Caching API Security document for publication

Project Scope

This document WILL address:
  • Security recommendations for the general use of the Open Caching APIs
  • Specification of one or more Security Profiles for secure communication between Open Caching Controllers using the OC APIs. This includes gathering already defined state-of-the-art mechanisms including transport protocols, methods for issuing tokens and their types, which are recommended for use.
This document WILL NOT address:
  • Enforcement of Security mechanisms beyond the scope defined in the Open Caching Architecture document
  • Specification of new mechanisms for issuing tokens, or the token itself

Contributors

The following members have contributed to this project. Click on their name to visit their profile. If they have not published their profile, the link will redirect to their LinkedIn profile.

Presentations

The following presentations delivered during Open Caching working group sessions may provide additional information about this project.

Have A Question ABout Membership?

Schedule A Meeting

Send An Email

Don’t want to schedule a face-to-face meeting just now? No problem. Simply send your membership question to info@streamingvideoalliance.org or fill out the form below and someone will get back to you as soon as possible.

"*" indicates required fields

Name*
Email*
This field is hidden when viewing the form