Reference monitors for security and interoperability in OAuth 2.0

2Citations
Citations of this article
6Readers
Mendeley users who have this article in their library.
Get full text

Abstract

OAuth 2.0 is a recent IETF standard devoted to providing authorization to clients requiring access to specific resources over HTTP. It has been pointed out that this framework is potentially subject to security issues, as well as difficulties concerning the interoperability between protocol participants and application evolution. As we show in this paper, there are indeed multiple reasons that make this protocol hard to implement and impede interoperability in the presence of different kinds of client. Our main contribution consists in a framework that harnesses a type-based policy language and aspect-based support for protocol adaptation through flexible reference monitors in order to handle security, interoperability and evolution issues of OAuth 2.0. We apply our framework in the context of three scenarios that make explicit variations in the protocol and show how to handle those issues. © 2014 Springer-Verlag Berlin Heidelberg.

Cite

CITATION STYLE

APA

Cherrueau, R. A., Douence, R., Royer, J. C., Südholt, M., De Oliveira, A. S., Roudier, Y., & Dell’Amico, M. (2014). Reference monitors for security and interoperability in OAuth 2.0. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 8247 LNCS, pp. 235–249). Springer Verlag. https://doi.org/10.1007/978-3-642-54568-9_15

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free