A Set of Simple Authentication and Security Layer (SASL) Mechanisms for OAuth

A Set of Simple Authentication and Security Layer (SASL) Mechanisms for OAuth
复制标题

一组用于 OAuth 的简单身份验证和安全层 (SASL) 机制

DOI:
10.17487/rfc7628
复制
发表时间:
2015
期刊:
RFC
影响因子:
--
通讯作者:
H. Tschofenig
H. Tschofenig
中科院分区:
--
文献类型:
--
作者:
William J. Mills;T. Showalter;H. Tschofenig

文献摘要

被引文献

相似文献

OAuth 使第三方应用程序能够获得对某个内容的有限访问 受保护的资源,或者代表资源所有者 协调批准交互或允许第三方 应用程序以自己的名义获取访问权限。本文档定义 应用程序客户端如何使用通过 OAuth 获得的凭据 用于访问受保护的简单身份验证和安全层 (SASL) 资源服务器上的资源。因此,它使定义的方案成为可能 在非基于 HTTP 的应用程序协议的 OAuth 框架内。 客户端通常存储用户的长期凭证。这确实, 然而,会导致重大的安全漏洞,例如, 当此类凭证泄露时。 OAuth 使用的显着优势 在这些客户端中,密码被共享秘密替换 具有较高熵,即令牌。代币通常提供有限的 访问权限,可以单独管理和撤销 用户的长期密码。
OAuth enables a third-party application to obtain limited access to a protected resource, either on behalf of a resource owner by orchestrating an approval interaction or by allowing the third-party application to obtain access on its own behalf. This document defines how an application client uses credentials obtained via OAuth over the Simple Authentication and Security Layer (SASL) to access a protected resource at a resource server. Thereby, it enables schemes defined within the OAuth framework for non-HTTP-based application protocols. Clients typically store the user's long-term credential. This does, however, lead to significant security vulnerabilities, for example, when such a credential leaks. A significant benefit of OAuth for usage in those clients is that the password is replaced by a shared secret with higher entropy, i.e., the token. Tokens typically provide limited access rights and can be managed and revoked separately from the user's long-term password.