首页> 外文会议>International Joint Conference on e-Business and Telecommunications >A Wizard-based Approach for Secure Code Generation of Single Sign-On and Access Delegation Solutions for Mobile Native Apps
【24h】

A Wizard-based Approach for Secure Code Generation of Single Sign-On and Access Delegation Solutions for Mobile Native Apps

机译:基于向导的安全代码生成单点登录和移动原生应用程序的访问委派解决方案的方法

获取原文

摘要

Many available mobile applications (apps) have poorly implemented Single Sign-On and Access Delegation solutions leading to serious security issues. This could be caused by inexperienced developers who prioritize the implementation of core functionalities and/or misunderstand security critical parts. The situation is even worse in complex API scenarios where the app interacts with several providers. To address these problems, we propose a novel wizard-based approach that guides developers to integrate multiple third-party Identity Management (IdM) providers in their apps, by (i) "enforcing" the usage of best practices for native apps, (ii) avoiding the need to download several SDKs and understanding their online documentations (a list of known IdM providers with their configuration information is embedded within our approach), and (iii) automatically generating the code to enable the communication with the different IdM providers. The effectiveness of the proposed approach has been assessed by implementing an Android Studio plugin and using it to integrate several IdM providers, such as OKTA, Auth0, Microsoft, and Google.
机译:许多可用的移动应用程序(应用程序)实现了较差的单点登录和访问委派解决方案,导致严重的安全问题。这可能是由未经经验的开发人员造成的,这些开发商优先考虑实施核心功能和/或误解安全关键部分。在应用程序与多个提供商交互的复杂API方案中,情况更糟糕。为解决这些问题,我们提出了一种基于新的向导的方法,指导开发人员将多个第三方身份管理(IDM)提供商集成在应用程序中,(i)“强制执行”本机应用程序的最佳实践的使用(II )避免需要下载多个SDK并理解其在线文档(其中包含其配置信息的已知IDM提供程序列表),(iii)自动生成代码以启用与不同的IDM提供程序的通信。通过实施Android Studio插件并使用它来集成几个IDM提供程序,例如OKTA,Auth0,Microsoft和Google等方法,已评估该方法的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号