首页> 外文会议>International workshop on information security application >A Study of OAuth 2.0 Risk Notification and Token Revocation from Resource Server
【24h】

A Study of OAuth 2.0 Risk Notification and Token Revocation from Resource Server

机译:资源服务器的OAuth 2.0风险通知和令牌吊销研究

获取原文

摘要

OAuth was created to simplify authentication procedure. OAuth is a protocol that allows access to the user's assets in 3rd party web sites or applications without exposing the user's identity and credential. OAuth can be used to grant the access rights for the user without exposing the user's information to third parties. By utilizing the Token issued by the Authorization Server, client is able to gain access to the resources in the Resource Server. However, in current standards, the restrictions of token usage are not clearly defined. Although it specified Token expiration time, in reality, malicious client can reuse the Token to access Resource server. The existing Token Revocation operation has been carried out in a way that the client performs Revocation by requesting to the Authorization Server when special cases occur such as logout or identity change by resource owner. The revocation does not happen for the case that malicious code targets the Resource Server. This paper proposes a method for revoking the Token by requesting Revocation when the Resource Server performs abnormal behaviors by using Token.
机译:创建OAuth是为了简化身份验证过程。 OAuth是一种协议,它允许在不暴露用户身份和凭据的情况下访问第三方网站或应用程序中的用户资产。 OAuth可以用于授予用户访问权限,而无需将用户信息暴露给第三方。通过利用授权服务器发出的令牌,客户端可以访问资源服务器中的资源。但是,在当前的标准中,没有明确定义令牌使用的限制。尽管它指定了令牌的到期时间,但实际上,恶意客户端可以重用令牌来访问资源服务器。现有的令牌吊销操作已通过以下方式执行:客户端在发生特殊情况(例如注销或资源所有者的身份更改)时向授权服务器发出请求,以执行吊销。对于恶意代码针对资源服务器的情况,不会撤销。本文提出了一种在资源服务器使用令牌执行异常行为时通过请求吊销来吊销令牌的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号