一种适用于WoT架构的资源鉴权方法
发布时间:2018-03-02 23:21
本文选题:WoT 切入点:用户多角色 出处:《小型微型计算机系统》2017年04期 论文类型:期刊论文
【摘要】:OAuth(Open standard for Authorization)是一种基于Web的用于开放授权的互联网标准协议,在众多基于Web的应用平台中得到广泛应用,但是该机制应用在WoT架构下时面临许多挑战.其一,在OAuth协议的应用场景中,一般不会出现用户作为部分资源的拥有者,同时又作为其他资源的使用者的情况,所以OAuth协议不能适应WoT架构下用户多角色的特点.其二,OAuth协议本身并没有提供流量控制功能,而在WoT架构下泛在资源供应者需要通过流量控制来防止用户进行恶意访问.本文新提出了一种WoT架构下面向多角色用户的资源访问控制方法,解决了现有协议不能满足WoT架构下用户具有多种角色的特性,并且可以满足资源提供者进行流量控制的要求.
[Abstract]:OAuth(Open standard for Authorization is an Internet standard protocol for open authorization based on Web, which is widely used in many Web based application platforms. However, it faces many challenges when it is applied in WoT architecture. In the application scenario of OAuth protocol, there is generally no user as the owner of part of the resource, but also as the user of other resources. Therefore, the OAuth protocol can not adapt to the characteristics of multi-role users under the WoT architecture. Secondly, OAuth protocol itself does not provide flow control functions. In the WoT framework, the ubiquitous resource providers need to prevent malicious access through flow control. In this paper, a new resource access control method for multi-role users under the WoT architecture is proposed. It solves the problem that the existing protocol can not meet the requirements of the WoT architecture that the user has many roles and can meet the requirements of the resource provider to control the flow.
【作者单位】: 中国科学技术大学计算机科学与技术学院;中国科学技术大学苏州研究院网络计算与信息安全研究中心;
【基金】:安徽省自然科学基金项目(1408085MKL08)资助
【分类号】:TP393.08
【相似文献】
相关硕士学位论文 前4条
1 屠s,
本文编号:1558551
本文链接:https://www.wllwen.com/guanlilunwen/ydhl/1558551.html