{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,11]],"date-time":"2026-04-11T01:24:30Z","timestamp":1775870670192,"version":"3.50.1"},"reference-count":131,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2023,3,14]],"date-time":"2023-03-14T00:00:00Z","timestamp":1678752000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,3,14]],"date-time":"2023-03-14T00:00:00Z","timestamp":1678752000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Requirements Eng"],"published-print":{"date-parts":[[2023,9]]},"DOI":"10.1007\/s00766-023-00401-2","type":"journal-article","created":{"date-parts":[[2023,3,26]],"date-time":"2023-03-26T23:09:11Z","timestamp":1679872151000},"page":"441-479","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["WEBAPIK: a body of structured knowledge on designing web APIs"],"prefix":"10.1007","volume":"28","author":[{"given":"Mahsa H.","family":"Sadi","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eric","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,3,14]]},"reference":[{"key":"401_CR1","doi-asserted-by":"crossref","unstructured":"Jansen S, Finkelstein A, Brinkkemper S (2009) A sense of community: a research agenda for software ecosystems. In: Proceedings of 31st international conference on software engineering\u2014companion volume, IEEE. pp 187\u2013190","DOI":"10.1109\/ICSE-COMPANION.2009.5070978"},{"key":"401_CR2","doi-asserted-by":"crossref","unstructured":"Sadi MH, Yu E (2014) Analyzing the evolution of software development: from creative chaos to software ecosystems. In: Eighth international conference on research challenges in information science (RCIS), IEEE. pp 1\u201311","DOI":"10.1109\/RCIS.2014.6861055"},{"key":"401_CR3","unstructured":"Tan L, Wang N (2010) Future internet: the internet of things. In: 2010 3rd international conference on advanced computer theory and engineering (ICACTE), IEEE. vol 5, pp V5\u2013376"},{"key":"401_CR4","doi-asserted-by":"crossref","unstructured":"Bosch J (2010) Architecture challenges for software ecosystems. In: Proceedings of the fourth European conference on software architecture: companion volume, ACM. pp 93\u201395","DOI":"10.1145\/1842752.1842776"},{"key":"401_CR5","doi-asserted-by":"crossref","unstructured":"Vukovic M, Laredo J, Rajagopal S (2014) API terms and conditions as a service. In: 2014 IEEE international conference on services computing, IEEE. pp 386\u2013393","DOI":"10.1109\/SCC.2014.58"},{"issue":"1","key":"401_CR6","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1016\/j.clsr.2009.11.008","volume":"26","author":"RH Weber","year":"2010","unstructured":"Weber RH (2010) Internet of Things-New security and privacy challenges. Comput Law Secur Rev 26(1):23\u201330","journal-title":"Comput Law Secur Rev"},{"key":"401_CR7","doi-asserted-by":"publisher","first-page":"146","DOI":"10.1016\/j.comnet.2014.11.008","volume":"76","author":"S Sicari","year":"2015","unstructured":"Sicari S, Rizzardi A, Grieco LA, Coen-Porisini A (2015) Security, privacy, and trust in Internet of Things: the road ahead. Comput Netw 76:146\u2013164","journal-title":"Comput Netw"},{"key":"401_CR8","doi-asserted-by":"crossref","unstructured":"Stylos J, Myers B (2007) Mapping the space of API design decisions. In: Visual languages and human-centric computing, 2007. VL\/HCC 2007. In: IEEE symposium on IEEE. pp 50\u201360","DOI":"10.1109\/VLHCC.2007.44"},{"issue":"6","key":"401_CR9","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1145\/2896587","volume":"59","author":"BA Myers","year":"2016","unstructured":"Myers BA, Stylos J (2016) Improving API usability. Commun ACM 59(6):62\u201369","journal-title":"Commun ACM"},{"key":"401_CR10","doi-asserted-by":"crossref","unstructured":"Siriwardena P (2014) Advanced API security: securing APIs with OAuth 2.0, OpenID Connect, JWS, and JWE Apress, Berkeley, CA","DOI":"10.1007\/978-1-4302-6817-8_7"},{"key":"401_CR11","unstructured":"De B (2017) API management: an Architect's guide to developing and managing APIs for your organization, 1st edn. Apress, Berkeley, CA March 2017"},{"key":"401_CR12","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4842-3555-3","volume-title":"Practical API architecture and development with Azure and AWS","author":"T Vijayakumar","year":"2018","unstructured":"Vijayakumar T (2018) Practical API architecture and development with Azure and AWS. Apress, Berkeley, CA"},{"key":"401_CR13","volume-title":"API security in action","author":"N Madden","year":"2020","unstructured":"Madden N (2020) API security in action. Manning Publications, New York"},{"key":"401_CR14","unstructured":"Richardson C Pattern: API Gateway. Backend for Front-End, 37-40, Available at http:\/\/microservices.io\/patterns\/apigateway.html"},{"key":"401_CR15","unstructured":"RFC 6749 (2012) The OAuth 2.0 authorization framework, Available at https:\/\/www.rfc-editor.org\/rfc\/rfc6749."},{"key":"401_CR16","unstructured":"Sakimura N, Bradley D, de Mederiso B, Jones M, Jay E (2012) OpenID connect standard 1.0-draft 09, Available at https:\/\/openid.net\/specs\/openid-connect-standard-1_0-09.html."},{"key":"401_CR17","doi-asserted-by":"crossref","unstructured":"Sun ST, Beznosov K (2012) The devil is in the (implementation) details: an empirical analysis of OAuth SSO systems. In: Proceedings of the 2012 ACM conference on Computer and communications security, ACM. pp 378\u2013390","DOI":"10.1145\/2382196.2382238"},{"key":"401_CR18","doi-asserted-by":"crossref","unstructured":"Li W, Mitchell CJ (2016) Analyzing the security of Google\u2019s implementation of OpenID Connect. In: International conference on detection of intrusions and malware, and vulnerability assessment, Springer, Cham. pp 357\u2013376","DOI":"10.1007\/978-3-319-40667-1_18"},{"key":"401_CR19","doi-asserted-by":"crossref","unstructured":"Cataldo M, Herbsleb JD (2010) Architecting in software ecosystems: interface translucence as an enabler for scalable collaboration. In: Proceedings of the fourth European conference on software architecture: companion volume, ACM. pp 65\u201372","DOI":"10.1145\/1842752.1842772"},{"key":"401_CR20","doi-asserted-by":"crossref","unstructured":"Bloch J (2006) How to design a good API and why it matters. In: Companion to the 21st ACM SIGPLAN symposium on Object-oriented programming systems, languages, and applications, ACM. pp 506\u2013507","DOI":"10.1145\/1176617.1176622"},{"issue":"5","key":"401_CR21","doi-asserted-by":"publisher","first-page":"46","DOI":"10.1145\/1506409.1506424","volume":"52","author":"M Henning","year":"2009","unstructured":"Henning M (2009) API design matters. Commun ACM 52(5):46\u201356","journal-title":"Commun ACM"},{"key":"401_CR22","unstructured":"Kitchenham B (2004) Procedures for performing systematic reviews. Keele, UK, Keele University, Technical report TR\/SE-0401, 1\u201326"},{"issue":"1","key":"401_CR23","doi-asserted-by":"publisher","first-page":"58","DOI":"10.1109\/MS.2005.6","volume":"22","author":"T Dyba","year":"2005","unstructured":"Dyba T, Kitchenham BA, Jorgensen M (2005) Evidence-based software engineering for practitioners. IEEE Softw 22(1):58\u201365","journal-title":"IEEE Softw"},{"key":"401_CR24","doi-asserted-by":"crossref","unstructured":"Wohlin C (2014) Guidelines for snowballing in systematic literature studies and a replication in software engineering. In: Proceedings of the 18th international conference on evaluation and assessment in software engineering, pp 1\u201310","DOI":"10.1145\/2601248.2601268"},{"key":"401_CR25","volume-title":"An introduction to qualitative research","author":"U Flick","year":"2009","unstructured":"Flick U (2009) An introduction to qualitative research. Sage, Thousand Oaks"},{"key":"401_CR26","volume-title":"The coding manual for qualitative researchers","author":"J Salda\u00f1a","year":"2009","unstructured":"Salda\u00f1a J (2009) The coding manual for qualitative researchers. Sage, Thousand Oaks"},{"issue":"2","key":"401_CR27","doi-asserted-by":"publisher","first-page":"237","DOI":"10.1177\/1098214005283748","volume":"27","author":"DR Thomas","year":"2006","unstructured":"Thomas DR (2006) A general inductive approach for analyzing qualitative evaluation data. Am J Eval 27(2):237\u2013246","journal-title":"Am J Eval"},{"issue":"4","key":"401_CR28","first-page":"1","volume":"54","author":"A Hogan","year":"2020","unstructured":"Hogan A, Blomqvist E, Cochez M, d\u2019Amato C, de Melo G, Gutierrez C, Labra Gayo JE, Kirrane S, Neumaier S, Polleres A, Navigli R, Ngonga Ngomo AC, Rashid SM, Rula A, Schmelzeisen L, Sequeda J, Staab S, Zimmermann A (2020) Knowl Graphs ACM Comput Surv (CSUR) 54(4):1\u201337","journal-title":"Knowl Graphs ACM Comput Surv (CSUR)"},{"key":"401_CR29","unstructured":"Sadi M H (2020) Assisting with API design through reusing design knowledge. Doctoral dissertation, University of Toronto (Canada)"},{"key":"401_CR30","unstructured":"Pillai S, Iijima K, O\u2019Neill M, Santoro J, Jain A, Ryan F (2021) Magic quadrant for full life cycle API management. The Gartner Group"},{"key":"401_CR31","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4615-5269-7","volume-title":"Non-functional requirements in software engineering","author":"L Chung","year":"2000","unstructured":"Chung L, Nixon BA, Yu E, Mylopoulos J (2000) Non-functional requirements in software engineering, vol 5. Springer, Berlin"},{"key":"401_CR32","doi-asserted-by":"crossref","unstructured":"Gamma E, Helm R, Johnson R, Vlissides J (1993) Design patterns: abstraction and reuse of object-oriented design. In: European conference on object-oriented programming, pp 406\u2013431","DOI":"10.1007\/3-540-47910-4_21"},{"key":"401_CR33","unstructured":"ISO\/IEC TS 25011: 2017 Information technology\u2014systems and Software Quality Requirements and Evaluation (SQuaRE)\u2014service quality models, Available at: https:\/\/www.iso.org\/obp\/ui#iso:std:iso-iec:ts:25011:ed-1:v2:en."},{"key":"401_CR34","volume-title":"Software architecture in practice","author":"L Bass","year":"2003","unstructured":"Bass L, Clements P, Kazman R (2003) Software architecture in practice. Addison-Wesley Professional, Boston"},{"issue":"6","key":"401_CR35","doi-asserted-by":"publisher","first-page":"42","DOI":"10.1109\/52.469759","volume":"12","author":"PB Kruchten","year":"1995","unstructured":"Kruchten PB (1995) The 4+1 view model of architecture. IEEE Softw 12(6):42\u201350","journal-title":"IEEE Softw"},{"key":"401_CR36","unstructured":"Akana Documents, How to Accelerate API adoption\u2014available at https:\/\/www.akana.com\/blog\/api-adoption on 2019-08-13"},{"key":"401_CR37","doi-asserted-by":"crossref","unstructured":"Bermbach D, Wittern E (2016) Benchmarking web API quality. In: International conference on web engineering. Springer, Cham, pp 188\u2013206","DOI":"10.1007\/978-3-319-38791-8_11"},{"key":"401_CR38","doi-asserted-by":"crossref","unstructured":"Zghidi A, Hammouda I, Hnich B, Knauss E (2017) On the role of fitness dimensions in API design assessment-an empirical investigation. In: 2017 IEEE\/ACM 1st international workshop on API usage and evolution (WAPI). IEEE, pp 19\u201322","DOI":"10.1109\/WAPI.2017.4"},{"key":"401_CR39","unstructured":"Richardson C Building Micro-Services: Inter-process communication in a micro-service architecture, Available at https:\/\/www.nginx.com\/blog\/building-microservices-inter-process-communication\/"},{"issue":"3","key":"401_CR40","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1109\/52.676963","volume":"15","author":"SG McLellan","year":"1998","unstructured":"McLellan SG, Roesler AW, Tempest JT, Spinuzzi CI (1998) Building more usable APIs. IEEE Softw 15(3):78\u201386","journal-title":"IEEE Softw"},{"issue":"6","key":"401_CR41","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1109\/MS.2009.193","volume":"26","author":"MP Robillard","year":"2009","unstructured":"Robillard MP (2009) What makes APIs hard to learn? Answers from developers. IEEE Softw 26(6):27\u201334","journal-title":"IEEE Softw"},{"issue":"6","key":"401_CR42","doi-asserted-by":"publisher","first-page":"703","DOI":"10.1007\/s10664-010-9150-8","volume":"16","author":"MP Robillard","year":"2011","unstructured":"Robillard MP, Deline R (2011) A field study of API learning obstacles. Empir Softw Eng 16(6):703\u2013732","journal-title":"Empir Softw Eng"},{"key":"401_CR43","doi-asserted-by":"crossref","unstructured":"Piccioni M, Furia CA, Meyer B (2013) An empirical study of API usability. In: 2013 ACM\/IEEE international symposium on empirical software engineering and measurement, IEEE. pp 5\u201314","DOI":"10.1109\/ESEM.2013.14"},{"key":"401_CR44","doi-asserted-by":"crossref","unstructured":"Zibran MF, Eishita FZ, Roy CK (2011) Useful, but usable? factors affecting the usability of APIs. In: 18th working conference on reverse engineering (WCRE), 2011, IEEE. pp 151\u2013155","DOI":"10.1109\/WCRE.2011.26"},{"key":"401_CR45","doi-asserted-by":"publisher","first-page":"145","DOI":"10.1016\/j.infsof.2015.01.009","volume":"61","author":"T Scheller","year":"2015","unstructured":"Scheller T, K\u00fchn E (2015) Automated measurement of API usability: the API concepts framework. Inf Softw Technol 61:145\u2013162","journal-title":"Inf Softw Technol"},{"key":"401_CR46","doi-asserted-by":"crossref","unstructured":"Ko\u00e7i R, Franch X, Jovanovic P, Abell\u00f3 A (2020) A data-driven approach to measure the usability of web APIs. In: 2020 46th Euromicro conference on software engineering and advanced applications (SEAA), IEEE. pp 64\u201371","DOI":"10.1109\/SEAA51224.2020.00021"},{"key":"401_CR47","doi-asserted-by":"crossref","unstructured":"Bore C, Bore S (2005) Profiling software API usability for consumer electronics. In: 2005 digest of technical papers. International conference on consumer electronics, 2005. ICCE, IEEE. pp 155\u2013156","DOI":"10.1109\/ICCE.2005.1429764"},{"issue":"1","key":"401_CR48","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1002\/spe.2215","volume":"45","author":"GM Rama","year":"2015","unstructured":"Rama GM, Kak A (2015) Some structural measures of API usability. Softw Pract Exp 45(1):75\u2013110","journal-title":"Softw Pract Exp"},{"key":"401_CR49","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1016\/j.cosrev.2019.05.001","volume":"33","author":"I Rauf","year":"2019","unstructured":"Rauf I, Troubitsyna E, Porres I (2019) Systematic mapping study of API usability evaluation methods. Comput Sci Rev 33:49\u201368","journal-title":"Comput Sci Rev"},{"key":"401_CR50","doi-asserted-by":"publisher","first-page":"46","DOI":"10.1016\/j.infsof.2017.12.010","volume":"97","author":"E Mosqueira-Rey","year":"2018","unstructured":"Mosqueira-Rey E, Alonso-R\u00edos D, Moret-Bonillo V, Fern\u00e1ndez-Varela I, \u00c1lvarez-Est\u00e9vez D (2018) A systematic approach to API usability: taxonomy-derived criteria and a case study. Inf Softw Technol 97:46\u201363","journal-title":"Inf Softw Technol"},{"key":"401_CR51","doi-asserted-by":"crossref","unstructured":"Grill T, Polacek O, Tscheligi M (2012) Methods towards API usability: a structural analysis of usability problem categories. In: International conference on human-centered software engineering. Springer, Berlin, pp 164\u2013180","DOI":"10.1007\/978-3-642-34347-6_10"},{"key":"401_CR52","doi-asserted-by":"crossref","unstructured":"Xu J, Wang Y, Chen P, Wang P (2017) Lightweight and adaptive service API performance monitoring in highly dynamic cloud environment. In: 2017 IEEE international conference on services computing (SCC), IEEE. pp 35\u201343","DOI":"10.1109\/SCC.2017.80"},{"key":"401_CR53","doi-asserted-by":"crossref","unstructured":"Bermbach D, Wittern E (2019) Benchmarking web API quality\u2014revisited. arXiv preprint arXiv:1903.07712","DOI":"10.13052\/jwe1540-9589.19563"},{"key":"401_CR54","doi-asserted-by":"crossref","unstructured":"Adeborna E, Fletcher KK (2020) An empirical study of web API quality formulation. In: International conference on services computing. Springer, Cham, pp. 145\u2013153","DOI":"10.1007\/978-3-030-59592-0_10"},{"key":"401_CR55","unstructured":"MuleSoft. Guide to API Security, Available at https:\/\/www.mulesoft.com\/resources\/api\/api-security. Retrieved on 2022-08-15"},{"key":"401_CR56","unstructured":"Villanueva JC. Comparing load balancing algorithms. Available at https:\/\/www.jscape.com\/blog\/load-balancing-algorithms"},{"key":"401_CR57","unstructured":"Kemp Technologies White Paper. Load balancing algorithms and techniques, Available at https:\/\/kemptechnologies.com\/load-balancer\/load-balancing-algorithms-techniques\/"},{"key":"401_CR58","unstructured":"Microsoft Documents. Caching, Available at https:\/\/docs.microsoft.com\/en-us\/azure\/architecture\/best-practices\/caching"},{"key":"401_CR59","unstructured":"Richardson C. Building Micro-services: Using an API Gateway, Available at https:\/\/www.nginx.com\/blog\/building-microservices-using-an-api-gateway\/"},{"key":"401_CR60","volume-title":"Patterns of enterprise architecture applications","author":"M Fowler","year":"2002","unstructured":"Fowler M (2002) Patterns of enterprise architecture applications, 1st edn. Addison-Wesley Professional, Boston","edition":"1"},{"key":"401_CR61","unstructured":"Fowler M Gateway Pattern, Available at https:\/\/martinfowler.com\/eaaCatalog\/gateway.html"},{"key":"401_CR62","unstructured":"Richardson C Service Discovery in a Micro-Service Architecture. Available at https:\/\/www.nginx.com\/blog\/service-discovery-in-a-microservices-architecture\/"},{"key":"401_CR63","unstructured":"Richardson C Pattern: Self Registration. Available at https:\/\/microservices.io\/patterns\/self-registration.html"},{"key":"401_CR64","unstructured":"Richardson C Pattern: 3rd Party Registration. Available at https:\/\/microservices.io\/patterns\/3rd-party-registration.html"},{"key":"401_CR65","unstructured":"Dey S, Mulloy B (2012) Essential facade patterns\u2014API composition. Available at https:\/\/www.slideshare.net\/apigee\/api-facade-patterns-composition"},{"key":"401_CR66","unstructured":"Richardson C (2017) Pattern: API composition, Available at https:\/\/microservices.io\/patterns\/data\/api-composition.html. Retrieved on 2022-08-10"},{"key":"401_CR67","unstructured":"Dey S (2012) Essential API Facade Patterns\u2014synchronous to asynchronous conversion. Available at https:\/\/www.slideshare.net\/apigee\/essential-api-facade-patterns-synchronous-to-asynchronous-conversion-episode-4"},{"key":"401_CR68","unstructured":"Richardson C Pattern: Server-Side Service Discovery. https:\/\/microservices.io\/patterns\/server-side-discovery.html"},{"key":"401_CR69","unstructured":"Richardson C Pattern: Client-Side Service Discovery. Available at https:\/\/microservices.io\/patterns\/client-side-discovery.htmlhttps:\/\/microservices.io\/patterns\/client-side-discovery.html"},{"key":"401_CR70","unstructured":"Hohpe G, Woolf B Enterprise Integration Patterns. Available at https:\/\/www.enterpriseintegrationpatterns.com\/patterns\/messaging\/index.html"},{"key":"401_CR71","volume-title":"Enterprise integration patterns: designing, building, and deploying messaging solutions","author":"G Hohpe","year":"2004","unstructured":"Hohpe G, Woolf B (2004) Enterprise integration patterns: designing, building, and deploying messaging solutions. Addison-Wesley Professional, Boston"},{"key":"401_CR72","unstructured":"RFC 4158: Internet X509, Public key infrastructure: certification path building, Available at https:\/\/tools.ietf.org\/html\/rfc4158"},{"key":"401_CR73","unstructured":"RFC 5280: Internet X509, Public key infrastructure and certificate revocation list, Available at https:\/\/www.rfc-editor.org\/rfc\/rfc3280"},{"key":"401_CR74","unstructured":"OAuth 2.0, Available at https:\/\/oauth.net\/2\/"},{"key":"401_CR75","unstructured":"OpenID Connect, Available at https:\/\/openid.net\/connect\/"},{"key":"401_CR76","unstructured":"Google Cloud. Why and when to use API keys, Available at https:\/\/cloud.google.com\/endpoints\/docs\/openapi\/when-why-api-key"},{"key":"401_CR77","doi-asserted-by":"crossref","unstructured":"Stocker M, Zimmermann O, Zdun U, L\u00fcbke D, Pautasso C (2018) Interface quality patterns: communicating and improving the quality of microservices Apis. In: Proceedings of the 23rd European conference on pattern languages of programs, pp 1\u201316","DOI":"10.1145\/3282308.3282319"},{"key":"401_CR78","doi-asserted-by":"crossref","unstructured":"Tang L, Ouyang L, Tsai WT (2015) Multi-factor web API security for securing Mobile Cloud. In: 2015 12th international conference on fuzzy systems and knowledge discovery (FSKD), IEEE. pp 2163\u20132168","DOI":"10.1109\/FSKD.2015.7382287"},{"key":"401_CR79","unstructured":"Fowler, M Circuit Breaker, Available at https:\/\/martinfowler.com\/bliki\/CircuitBreaker.html"},{"key":"401_CR80","unstructured":"Montesi F, Weber J (2016) Circuit breakers, discovery, and API gateways in microservices. arXiv preprint, arXiv:1609.05830"},{"key":"401_CR81","unstructured":"Apigee Reference Material. Comparing Quota, Spike Arrest, and Concurrent Rate Limit Policies, Available at https:\/\/docs.apigee.com\/api-platform\/develop\/comparing-quota-spike-arrest-and-concurrent-rate-limit-policies"},{"key":"401_CR82","doi-asserted-by":"crossref","unstructured":"Wilson Y, Hingnikar A (2019) Solving identity management in modern applications: demystifying OAuth 2.0, OpenID Connect, and SAML 2.0. Apress","DOI":"10.1007\/978-1-4842-5095-2"},{"key":"401_CR83","doi-asserted-by":"crossref","unstructured":"Fett D, K\u00fcsters R, Schmitz G (2016) A comprehensive formal security analysis of OAuth 2.0. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, pp 1204\u20131215","DOI":"10.1145\/2976749.2978385"},{"key":"401_CR84","doi-asserted-by":"crossref","unstructured":"Yang F, Manoharan S (2013) A security analysis of the OAuth protocol. In: 2013 IEEE Pacific Rim conference on communications, computers and signal processing (PACRIM), IEEE. pp 271\u2013276","DOI":"10.1109\/PACRIM.2013.6625487"},{"key":"401_CR85","doi-asserted-by":"crossref","unstructured":"Li W, Mitchell CJ (2014) Security issues in OAuth 2.0 SSO implementations. In: International conference on information security. Springer, Cham. pp 529\u2013541","DOI":"10.1007\/978-3-319-13257-0_34"},{"key":"401_CR86","doi-asserted-by":"crossref","unstructured":"Ferry E, Raw JO, Curran K (2015) Security evaluation of the OAuth 2.0 framework. Information and Computer Security","DOI":"10.1108\/ICS-12-2013-0089"},{"key":"401_CR87","doi-asserted-by":"crossref","unstructured":"Darwish M, Ouda A (2015) Evaluation of an OAuth 2.0 protocol implementation for web server applications. In: 2015 International conference and workshop on computing and communication (IEMCON). IEEE, pp 1\u20134","DOI":"10.1109\/IEMCON.2015.7344461"},{"key":"401_CR88","first-page":"103091","volume":"65","author":"J Singh","year":"2022","unstructured":"Singh J, Chaudhary NK (2022) OAuth 2.0: architectural design augmentation for mitigation of common security vulnerabilities. J Inf Secur Appl 65:103091","journal-title":"J Inf Secur Appl"},{"key":"401_CR89","doi-asserted-by":"crossref","unstructured":"Blazquez A, Tsiatsis V, Vandikas K (2015) Performance evaluation of OpenID Connect for an IOT information market-place. In: 2015 IEEE 81st, Vehicular Technology Conference (VTC Spring), pp 1\u20136","DOI":"10.1109\/VTCSpring.2015.7146004"},{"key":"401_CR90","doi-asserted-by":"crossref","unstructured":"Hammann S, Sasse R, Basin D (2020) Privacy-preserving openid connect. In: Proceedings of the 15th ACM Asia conference on computer and communications security, pp 277\u2013289","DOI":"10.1145\/3320269.3384724"},{"key":"401_CR91","doi-asserted-by":"crossref","unstructured":"Li W, Mitchell CJ (2020) User access privacy in OAuth 2.0 and OpenID connect. In: 2020 IEEE European symposium on security and privacy workshops (EuroSandPW), IEEE. pp 664\u20136732","DOI":"10.1109\/EuroSPW51379.2020.00095"},{"key":"401_CR92","doi-asserted-by":"crossref","unstructured":"Mainka C, Mladenov V, Schwenk J, Wich T (2017) Sok: single sign-on security\u2014an evaluation of openid connect. In: 2017 IEEE European symposium on security and privacy (EuroSandP), IEEE. pp 251\u2013266","DOI":"10.1109\/EuroSP.2017.32"},{"key":"401_CR93","doi-asserted-by":"crossref","unstructured":"Fett D, K\u00fcsters R, Schmitz G (2017) The web SSO standard openid connect: in-depth formal security analysis and security guidelines. In: 2017 IEEE 30th computer security foundations symposium (CSF), IEEE. pp 189\u2013202","DOI":"10.1109\/CSF.2017.20"},{"key":"401_CR94","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cose.2019.03.003","volume":"84","author":"J Navas","year":"2019","unstructured":"Navas J, Beltr\u00e1n M (2019) Understanding and mitigating OpenID connect threats. Comput Secur 84:1\u201316","journal-title":"Comput Secur"},{"key":"401_CR95","doi-asserted-by":"crossref","unstructured":"Li W, Mitchell CJ, Chen T (2019) Oauthguard: Protecting user security and privacy with oauth 2.0 and openid connect. In: Proceedings of the 5th ACM workshop on security standardisation research workshop, pp 35\u201344","DOI":"10.1145\/3338500.3360331"},{"key":"401_CR96","unstructured":"Mladenov V, Mainka C, Schwenk J (2015) On the security of modern single sign-on protocols: second-order vulnerabilities in openid connect. arXiv preprint arXiv:1508.04324."},{"key":"401_CR97","doi-asserted-by":"crossref","unstructured":"Behnel S, Fiege L, Muhl G (2006) On quality-of-service and publish-subscribe. In: 26th IEEE international conference on distributed computing systems workshops (ICDCSW'06), IEEE. pp 20\u201320","DOI":"10.1109\/ICDCSW.2006.77"},{"key":"401_CR98","doi-asserted-by":"crossref","unstructured":"Cugola G, Margara A, Migliavacca M (2009) Context-aware publish-subscribe: model, implementation, and evaluation. In: 2009 IEEE symposium on computers and communications, IEEE. pp 875\u2013881","DOI":"10.1109\/ISCC.2009.5202277"},{"key":"401_CR99","doi-asserted-by":"crossref","unstructured":"Costa P, Migliavacca M, Picco GP, Cugola G (2004) Epidemic algorithms for reliable content-based publish-subscribe: an evaluation. In: 24th international conference on distributed computing systems, 2004. Proceedings, IEEE, pp 552\u2013561","DOI":"10.1109\/ICDCS.2004.1281622"},{"key":"401_CR100","doi-asserted-by":"publisher","first-page":"100538","DOI":"10.1016\/j.iot.2022.100538","volume":"19","author":"A Lazidis","year":"2022","unstructured":"Lazidis A, Tsakos K, Petrakis EG (2022) Publish-Subscribe approaches for the IoT and the cloud: functional and performance evaluation of open-source systems. Internet of Things 19:100538","journal-title":"Internet of Things"},{"issue":"3","key":"401_CR101","doi-asserted-by":"publisher","first-page":"318","DOI":"10.1016\/j.future.2009.09.001","volume":"26","author":"S Oh","year":"2010","unstructured":"Oh S, Kim JH, Fox G (2010) Real-time performance analysis for publish\/subscribe systems. Futur Gener Comput Syst 26(3):318\u2013323","journal-title":"Futur Gener Comput Syst"},{"key":"401_CR102","doi-asserted-by":"crossref","unstructured":"Wardana AA, Perdana RS (2018) Access control on internet of things based on publish\/subscribe using authentication server and secure protocol. In: 2018 10th international conference on information technology and electrical engineering (ICITEE), IEEE. pp 118\u2013123","DOI":"10.1109\/ICITEED.2018.8534855"},{"key":"#cr-split#-401_CR103.1","doi-asserted-by":"crossref","unstructured":"Taibi D, Lenarduzzi V, Pahl C (2018) Architectural patterns for microservices: a systematic mapping study. In: CLOSER 2018: proceedings of the 8th international conference on cloud computing and services science","DOI":"10.5220\/0006798302210232"},{"key":"#cr-split#-401_CR103.2","unstructured":"Funchal, Madeira, Portugal, 19-21 March 2018. SciTePress"},{"key":"401_CR104","doi-asserted-by":"crossref","unstructured":"Tighilt R, Abdellatif M, Moha N, Mili H, Boussaidi GE, Privat J, Gu\u00e9h\u00e9neuc YG (2020) On the study of microservices antipatterns: a catalog proposal. In: Proceedings of the European conference on pattern languages of programs 2020, pp 1\u201313","DOI":"10.1145\/3424771.3424812"},{"key":"401_CR105","doi-asserted-by":"crossref","unstructured":"Siegmund J, Siegmund N, Apel S (2015) Views on internal and external validity in empirical software engineering. In: 2015 IEEE\/ACM 37th IEEE international conference on software engineering, IEEE, vol 1, pp 9\u201319","DOI":"10.1109\/ICSE.2015.24"},{"key":"401_CR106","doi-asserted-by":"crossref","unstructured":"Chung L, Supakkul S (2006) Capturing and reusing functional and non-functional requirements knowledge: a goal-object pattern approach. In: 2006 IEEE international conference on information reuse and integration, IEEE. pp 539\u2013544","DOI":"10.1109\/IRI.2006.252471"},{"issue":"4","key":"401_CR107","doi-asserted-by":"publisher","first-page":"436","DOI":"10.1016\/j.infsof.2009.10.010","volume":"52","author":"A Casamayor","year":"2010","unstructured":"Casamayor A, Godoy D, Campo M (2010) Identification of non-functional requirements in textual specifications: a semi-supervised learning approach. Inf Softw Technol 52(4):436\u2013445","journal-title":"Inf Softw Technol"},{"key":"401_CR108","doi-asserted-by":"crossref","unstructured":"Supakkul, S, Chung, L (2010) Visualizing non-functional requirements patterns. In: 2010 fifth international workshop on requirements engineering visualization, IEEE. pp 25\u201334","DOI":"10.1109\/REV.2010.5625663"},{"key":"401_CR109","doi-asserted-by":"crossref","unstructured":"Sadi MH, Yu E (2017) Modeling and analyzing openness trade-offs in software platforms: a goal-oriented approach. In: International working conference on requirements engineering: foundation for software quality. Springer, Cham, pp 33\u201349","DOI":"10.1007\/978-3-319-54045-0_3"},{"key":"401_CR110","doi-asserted-by":"crossref","unstructured":"Sadi MH, Yu E (2017) Accommodating openness requirements in software platforms: a goal-oriented approach. In: International conference on advanced information systems engineering. Springer, Cham, pp 44\u201359","DOI":"10.1007\/978-3-319-59536-8_4"},{"issue":"1","key":"401_CR111","volume":"X","author":"M Binkhonain","year":"2019","unstructured":"Binkhonain M, Zhao L (2019) A review of machine learning algorithms for identification and classification of non-functional requirements. Expert Syst Appl X(1):100001","journal-title":"Expert Syst Appl"},{"key":"401_CR112","unstructured":"Buschmann F, Henney K, Schmidt DC (2007) Pattern-oriented software architecture, on patterns and pattern languages, vol 5 Wiley, New York"},{"key":"401_CR113","doi-asserted-by":"crossref","unstructured":"Aridor Y, Lange DB (1998) Agent design patterns: elements of agent application design. In: Proceedings of the second international conference on Autonomous agents. pp 108\u2013115","DOI":"10.1145\/280765.280784"},{"key":"401_CR114","volume-title":"Headfirst design patterns","author":"E Freeman","year":"2008","unstructured":"Freeman E, Robson E, Bates B, Sierra K (2008) Headfirst design patterns. O\u2019Reilly Media Inc, Sebastopol"},{"key":"401_CR115","volume-title":"SOA design patterns (paperback)","author":"T Erl","year":"2008","unstructured":"Erl T (2008) SOA design patterns (paperback). Pearson Education, London"},{"issue":"5","key":"401_CR116","doi-asserted-by":"publisher","first-page":"853","DOI":"10.1109\/TVCG.2006.178","volume":"12","author":"J Heer","year":"2006","unstructured":"Heer J, Agrawala M (2006) Software design patterns for information visualization. IEEE Trans Visual Comput Graph 12(5):853\u2013860","journal-title":"IEEE Trans Visual Comput Graph"},{"issue":"5","key":"401_CR117","doi-asserted-by":"publisher","first-page":"1213","DOI":"10.1109\/TSE.2011.79","volume":"38","author":"C Zhang","year":"2011","unstructured":"Zhang C, Budgen D (2011) What do we know about the effectiveness of software design patterns? IEEE Trans Softw Eng 38(5):1213\u20131231","journal-title":"IEEE Trans Softw Eng"},{"issue":"2","key":"401_CR118","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1109\/52.506460","volume":"13","author":"B Boehm","year":"1996","unstructured":"Boehm B, In H (1996) Identifying quality-requirement conflicts. IEEE Softw 13(2):25\u201335","journal-title":"IEEE Softw"},{"issue":"1","key":"401_CR119","doi-asserted-by":"publisher","first-page":"43","DOI":"10.1109\/52.566427","volume":"14","author":"RT Monroe","year":"1997","unstructured":"Monroe RT, Kompanek A, Melton R, Garlan D (1997) Architectural styles, design patterns, and objects. IEEE Softw 14(1):43\u201352","journal-title":"IEEE Softw"},{"key":"401_CR120","doi-asserted-by":"crossref","unstructured":"Babar MA, Gorton I, Jeffery R (2005) Capturing and using software architecture knowledge for architecture-based software development. In: Fifth international conference on quality software (QSIC'05), IEEE. pp 169\u2013176","DOI":"10.1109\/QSIC.2005.17"},{"key":"401_CR121","doi-asserted-by":"publisher","first-page":"110714","DOI":"10.1016\/j.jss.2020.110714","volume":"169","author":"S Farshidi","year":"2020","unstructured":"Farshidi S, Jansen S, van der Werf JM (2020) Capturing software architecture knowledge for pattern-driven design. J Syst Softw 169:110714","journal-title":"J Syst Softw"},{"key":"401_CR122","doi-asserted-by":"crossref","unstructured":"Kruchten P (2010) Where did all this good architectural knowledge go? In: European conference on software architecture. Springer, Berlin, pp 5\u20136","DOI":"10.1007\/978-3-642-15114-9_2"},{"key":"401_CR123","doi-asserted-by":"crossref","unstructured":"Kazman R, Klein M, Barbacci M, Longstaff T, Lipson H, Carriere J (1998) The architecture trade-off analysis method. In: Fourth IEEE international conference on engineering of complex computer systems, 1998. ICECCS'98. Proceedings, IEEE. pp 68\u201378","DOI":"10.1109\/ICECCS.1998.706657"},{"issue":"6","key":"401_CR124","doi-asserted-by":"publisher","first-page":"918","DOI":"10.1016\/j.jss.2006.08.040","volume":"80","author":"A Tang","year":"2007","unstructured":"Tang A, Jin Y, Han J (2007) A rationale-based architecture model for design traceability and reasoning. J Syst Softw 80(6):918\u2013934","journal-title":"J Syst Softw"},{"key":"401_CR125","doi-asserted-by":"crossref","unstructured":"D\u00fcrschmid T, Kang E, Garlan D (2019) Trade-off-oriented development: making quality attribute trade-offs first-class. In: 2019 IEEE\/ACM 41st international conference on software engineering: new ideas and emerging results (ICSENIER), IEEE. pp 109\u2013112","DOI":"10.1109\/ICSE-NIER.2019.00036"},{"issue":"4","key":"401_CR126","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1109\/MS.2009.161","volume":"27","author":"M Robillard","year":"2009","unstructured":"Robillard M, Walker R, Zimmermann T (2009) Recommendation systems for software engineering. IEEE Softw 27(4):80\u201386","journal-title":"IEEE Softw"},{"key":"401_CR127","doi-asserted-by":"publisher","first-page":"156","DOI":"10.1016\/j.jss.2015.09.039","volume":"112","author":"B Costa","year":"2016","unstructured":"Costa B, Pires PF, Delicato FC, Merson P (2016) Evaluating REST architectures\u2014approach, tooling and guidelines. J Syst Softw 112:156\u2013180","journal-title":"J Syst Softw"},{"key":"401_CR128","unstructured":"Mathijssen M, Overeem M, Jansen S (2020) Identification of practices and capabilities in API management: a systematic literature review. arXiv preprint arXiv:2006.10481"},{"key":"401_CR129","unstructured":"Zimmermann O, Stocker M, L\u00fcbke D, Pautasso C, Zdun U (2019) Introduction to microservice API patterns (MAP)"},{"key":"401_CR130","doi-asserted-by":"crossref","unstructured":"Sadi MH, Yu E (2021) RAPID: a knowledge-based assistant for designing web APIs. Requirements Engineering, pp 1\u201352","DOI":"10.1007\/s00766-020-00342-0"}],"container-title":["Requirements Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00766-023-00401-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00766-023-00401-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00766-023-00401-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,7,13]],"date-time":"2023-07-13T11:05:10Z","timestamp":1689246310000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00766-023-00401-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,3,14]]},"references-count":131,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2023,9]]}},"alternative-id":["401"],"URL":"https:\/\/doi.org\/10.1007\/s00766-023-00401-2","relation":{},"ISSN":["0947-3602","1432-010X"],"issn-type":[{"value":"0947-3602","type":"print"},{"value":"1432-010X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,3,14]]},"assertion":[{"value":"5 February 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 February 2023","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"14 March 2023","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}