首页> 外文会议>IEEE International Symposium on Policies for Distributed Systems and Networks >DAuth: Fine-Grained Authorization Delegation for Distributed Web Application Consumers
【24h】

DAuth: Fine-Grained Authorization Delegation for Distributed Web Application Consumers

机译:Dauth:分布式Web应用程序消费者的细粒度授权委派

获取原文

摘要

Web applications are becoming the predominant means by which users interact with online content. However, current authentication approaches use a single authentication credential to manage access permissions, which is too inflexible for distributed programs with unique security and privacy requirements for each component. In this paper, we introduce DAuth, an authorization mechanism that allows fine-grained and flexible control of access permissions derived from a single authentication credential for distributed consumers of web applications. We implement DAuth as a proxy for a Twitter social networking application within our distributed Elastic Application framework and find it introduces negligible overhead and requires only minor modification of existing applications. Through our evaluation, we demonstrate DAuth improves on existing web authentication mechanisms to support distributed web application consumers and can be implemented as a proxy to web applications that do not wish to develop their own implementation.
机译:Web应用程序正在成为用户与在线内容交互的主要方法。但是,当前的身份验证方法使用单个身份验证凭证来管理访问权限,这对于具有每个组件的唯一安全性和隐私要求的分布式程序来说太不可能。在本文中,我们介绍了Dauth,一种授权机制,允许对来自Web应用程序的分布式消费者的单一认证凭证导出的访问权限进行微粒和灵活控制。我们在我们的分布式弹性应用程序框架内实现DAUTU作为Twitter社交网络应用程序的代理,并发现它引入可忽略的开销,并且只需要轻微修改现有应用程序。通过我们的评估,我们演示了Dauth,即支持分布式Web应用程序消费者的现有Web身份验证机制,并且可以实现为不希望开发自己实现的Web应用程序的代理。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号