【24h】

What We Can Learn from API Security

机译:我们可以从API安全中学到什么

获取原文
获取原文并翻译 | 示例

摘要

During the period when Mike and Bruce were looking for position papers for this workshop, I was rather busy because of a court case some of you may have heard about, so I'm going to go over the slides that I gave at Roger Needham's farewell do last month, with some extra material added. The subject is what API security teaches us in the wider world of protocols; so it's about protocol analysis, composability, computation, and the effects in the real world. How do we define a security protocol's world? Well that's changing: in the classic literature there are rules for dealing with information used to verify principals' claims to identity, such as passwords, PINs, crypto keys and timestamps. Now it's expanding to include other claims: such as claims to authorisation, or claims to creditworthiness, or claims to have a particular bank balance available for an electronic payment.
机译:在Mike和Bruce在寻找研讨会的立场书期间,由于有些人可能听说过法庭案件,我当时很忙,所以我要讲一下我在Roger Needham的告别中提供的幻灯片。上个月做了,增加了一些额外的材料。 API安全性在更广泛的协议世界中教会了我们什么?因此,它涉及协议分析,可组合性,计算以及现实世界中的影响。我们如何定义安全协议的世界?情况正在发生变化:在经典文献中,有一些规则用于处理用于验证校长对身份声明的信息,例如密码,PIN,加密密钥和时间戳。现在,它正在扩展,以包括其他索赔:例如授权索赔,信誉索赔或具有可用于电子支付的特定银行余额的索赔。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号