Integration of the OAuth and Web Service family security standards

被引:16
作者
Torroglosa-Garcia, Elena [1 ]
Perez-Morales, Antonio D. [2 ]
Martinez-Julia, Pedro [1 ]
Lopez, Diego R. [3 ]
机构
[1] Univ Murcia, Dept Commun & Informat Engn, E-30100 Murcia, Spain
[2] Spanish Natl Res & Educ Network, RedIRIS, Seville 41012, Spain
[3] Telefon I D, Madrid 28050, Spain
关键词
Security Token Service; Authentication; Authorization; WS-Security; OAuth; GEMBus;
D O I
10.1016/j.comnet.2012.11.027
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
There are more and more scenarios requiring the transparent integration of heterogeneous security services in order to facilitate application development, simplify deployment and provide a seamless user experience. One of the most common use cases occurs when resources make use of OAuth to provide a simple and flexible way to authorize clients in order to access protected resources. But different OAuth implementations normally use distinct types of authorization grant and access tokens. This heterogeneity can be tackled by leveraging on WS-Trust, which is especially intended to offer integration mechanisms among services that implement WS-* specifications. By integrating these mechanisms it is possible to reduce the complexity supported by the OAuth Authorization Server (AS), so easing the interoperability through the delegation of the issuance and validation processes. This work also proposes a solution to cover the needs of WS-Trust clients which intend to use OAuth resources. (C) 2013 Elsevier B.V. All rights reserved.
引用
收藏
页码:2233 / 2249
页数:17
相关论文
共 31 条
[1]   New Frontiers in Internet Network Management [J].
Al-Shaer, Ehab ;
Greenberg, Albert ;
Kalmanek, Charles ;
Maltz, David A. ;
Ng, T. S. Eugene ;
Xie, Geoffrey G. .
ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2009, 39 (05) :37-39
[2]  
[Anonymous], 2006, 4422 RFC IETF NETW W
[3]  
[Anonymous], 2012, IETF WG COMM AUTH TE
[4]  
[Anonymous], 2010, POSITION PAPER MANAG
[5]  
[Anonymous], 2010, PUBLIC KEY INFRASTRU
[6]  
Cantor S., 2005, ASSERTIONS PROTOCOLS
[7]  
Chappell D.A., 2004, Enterprise Service Bus
[8]  
Cooper D., 2008, 5280 RFC IETF NETW W
[9]  
Crockford D., 2006, RFC4627 IETF NETW WO
[10]  
DANTE Ltd, 2001, GEANT 2 PROJ