Best way to get data into Android app?
Just a little background. I am a professional asp.net/c#/sql programmer who has been learning Android for less than 2 days.
We have an existing .net website that stores a list of locations in MS SQL Server 2008 and I am trying to create an Android app that gets these locations and displays them on a google map.
The question is how to connect the application to the SQL database. I guess there are several options ...
1) Direct connection between the application and the remote database.
2) Create some kind of middle tier using asp.net that transforms the data into something more usable Java code in an Android application (remember I know practically NO java), exactly the same was what we have. net code that supplies JSON to our web applications.
3) Create a kind of web service to easily return XML results from a web server. Not sure how I would protect this so that only the android app can request data.
Any help or best practice advice would be really helpful. I think I just need to point in the general direction of a good strategy and I can fix that.
a source to share
Your security issue is one of the networking frameworks and protocols, not Android. OAUTH is becoming the standard way to do this, and using Google as an example, perhaps a better analogue would be accessing Google Docs?
here:
Actually implementation of handshake etc. may take a bit of work depending on how securely you would like to do it. Again, this is not really an "Android thing", as this is the first call to architecture, and once you make some of these architectural decisions, you can actually implement what you decide to do on Android or whatever.
Conceptually, exposing your data through web services and consuming it according to your UI is fine. You just have to cover up what your security strategy will be, OAuth or otherwise.
a source to share
Not sure how I would protect this so that only the android app can request data.
Your problem is bigger.
It does not only refer to point (3), it refers to any possible approach that you are about to take.
- If you publish any data on the Internet, it can be accessed with or without authentication.
- If authentication is used to access it, either one account key for each user, or one for many users.
- Once the user has the credentials, they can use it however they like, you cannot restrict it and not completely block the credentials themselves.
Now you go this way, that is one account key that is valid for all users, that is, the application has it and it uses it to get the data. The fact that the user himself could not now does not matter.
Remember: security through obscurity just doesn't work. Obscurity is just "another annoyance" if you want to break, it's like a dark room with valuables inside: darkness doesn't help, but that's not a reason for not blocking. And someone will steal something soon, it's just a matter of time.
a source to share
Native LDAP support for Android could be coming out pretty soon ( Many want it ), which can help with security (e.g. using Exchange Server to validate different user credentials rather than using one for an app)
In the meantime, however, the data may be more readily available than necessary. Is it sensitive?
a source to share
You cannot connect to remote DB, especially if it is MS SQL database (android can only work with SQLite).
Your best bet, knowing that you want to protect your data, is to create a server-side Java interface that will have access to your database.
Then you can create RMI or use sockets to send and receive data (including encrypted data).
a source to share
Under your data protection problem, I do this to solve your problem:
- Use json web service to communicate between mobile and your db. The db connection needs to be restored every time you access the db due to poor network connectivity of mobile devices. The webservice wraps one question nicely in a db.
- Use google gson to parse json into java data objects to be processed in your application.
- Create a Mapview with your overlay to display the items on the map.
The security issue is a problem that I've thought about a lot. If you want to restrict access to the database, the application must have some kind of key to authenticate with the web server. The problem is, someone might just open your application and look for that key, and then rebuild the traffic used in your application. You can use the key to connect https to your api website, this prevents others from connecting to the network connection, but the person who owns the phone can always access the key.
You can always make it harder for an attacker, but you can always spoof a phone app because the auth tokens must be on the phone. Some ways to make it trickier:
- encrypt the key inside your application, it makes it difficult to quickly search inside your class files and easily extract the key. But this is another layer of hiding, because the decryption key must be in your application.
- create a second key based on phone data, add imei hash, phone number, etc. The problem is that this data must be initially registered with the server, so it can simply be faked.
If you just want your data to be protected from being collected by a bot, the server only responds to a request that appears to come from a mobile phone. Block individual IPs that make hundreds of web service calls, etc.
a source to share