首页> 外文会议>IEEE International Conference on Big Data Science and Engineering >OAuth-SSO: A Framework to Secure the OAuth-based SSO Service for Packaged Web Applications
【24h】

OAuth-SSO: A Framework to Secure the OAuth-based SSO Service for Packaged Web Applications

机译:OAuth-SSO:用于保护基于OAuth的SSO服务的框架,用于打包Web应用程序

获取原文

摘要

The OAuth 2.0 is an authorization protocol gives authorization on the Web. Popular social networks like Facebook, Google and Twitter make their APIs based on the OAuth protocol to increase user experience of SSO and social sharing. It is an open standard for authorization and gives a process for third-party applications to obtain users' resources on the resource servers without sharing their login credentials. Single sign-on (SSO) is an identification method that makes allowance for websites to use other, rely on sites to confirm users. OAuth 2.0 is broadly used in Single Sign-On (SSO) service because of its simple implementation and coherence with a diversity of the third-party applications. It has been proved secure in different formal methods, but some vulnerabilities are revealed in practice. In this paper, we mention a general approach to improve the security of OAuth based SSO service for packaged web app. This paper proposes a modified method to execute OAuth flow from such applications with the help of Single sign-on (SSO) manages the life cycle of these applications.
机译:OAuth 2.0是授权协议,在Web上提供授权。像Facebook这样的流行社交网络,Google和Twitter就基于OAuth协议来提高SSO和社交共享的用户体验。它是一个用于授权的开放标准,并为第三方应用程序提供了一个过程,以便在不共享其登录凭据的情况下获取资源服务器上的用户资源。单点登录(SSO)是一种识别方法,可以为网站允许使用其他,依赖站点来确认用户。 OAuth 2.0广泛用于单点登录(SSO)服务,因为其简单的实现和连贯性,具有第三方应用程序的多样性。它已被证明是安全的不同形式方法,但在实践中揭示了一些漏洞。在本文中,我们提到了一种普遍的方法来提高基于OAuth的SSO服务的安全性的封装Web应用程序。本文提出了一种修改的方法,以便在单点登录(SSO)的帮助下从这些应用程序执行OAuth流量(SSO)管理这些应用程序的生命周期。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号