The third security factor includes token-based STS APIto-
Backend authentication, Public Key Infrastructure (PKI),
additional TLS and data transmission security, such as X.509
PKI [12], RSA or DSA key, FCC crystal structure, TLS
Handshake protocol [27], in which X.509 standard is broadly
adopted by enterprises API-to-backend security and app-toapp
security. The X.509 is an ITU Telecommunication
Standardization Sector (ITU-T) standard in cryptography for
a PKI and Privilege Management Infrastructure (PMI). X.509
specifies, amongst other things, standard formats for public
key certificates, certificate revocation lists, attribute
certificates, and a certification path validation algorithm.
Figure 5 describes an API-to-Backend X.509-based
certificate security architecture.