节点文献
OpenID与OAuth融合认证中令牌安全提升方法
A Token Security Improvement Method for OpenID and OAuth Collaborative Authentication
【摘要】 移动互联网、物联网的资源交换共享。需要一种开放的身份认证与授权机制。Open ID与OAuth融合能够满足需求,也被很多互联网公司的业务平台所采用。但令牌存放位置可导致令牌泄露,而融合协议频繁的重定向则增大了令牌泄露风险。本文通过对协议建立形式化表达模型,用软件工具分析了协议安全性,证明了令牌通过Cookie存放是问题所在。通过调整融合认证的体系结构,在认证过程参与的实体上应用本地多级信任缓存,可以减少30%~50%的认证信令,提高了令牌的安全性。针对令牌攻击及相关的安全建议,进行了改进前后的对比验证,实验结果表明该方法可有效抵御针对令牌的网路攻击,提升平台的安全性。
【Abstract】 An open identity authentication framework is needed for resource sharing in mobile internet and / or Web of Things( Wo T).The Open ID and OAuth collaborative framework meets the basic requirement and is adopt by some Internet companies. But the collaborative frame work could have the risk of Token Leaking. In this paper,we adjust the authentication framework and apply a multi- entity cache based method. These methods reduce the authentication process lower to 30% ~ 50% and increase the Token security. The experiment shows that this framework can defend the token theft well thus promote the security level of the authentication framework.
【Key words】 Wo T; Resource sharing; Authentication; Token; OpenID; OAuth;
- 【文献出处】 网络新媒体技术 ,Journal of Network New Media , 编辑部邮箱 ,2015年01期
- 【分类号】TP393.08
- 【被引频次】5
- 【下载频次】108