摘要
随着云计算技术的快速发展和各种云端应用的开展,云环境中用户身份认证和授权管理成为云安全的关键问题之一。OAuth 2.0规范草案较好解决了云环境下的用户授权问题,提出了四种授权类型。本文在OAuth 2.0规范基础上,针对应用比较广泛的Authorization Code模式提出了基于数字证书的IDP改进模型。论文最后讨论了改进模型的优势。
With the development of cloud computing technology and applications, the security of cloud computing about user authentication and authorization management became more important. The OAuth2.0 Authorization Protocol gives some advice about the issue of user authorization in the cloud environment. This article is base on the Authorization Code model of OAuth2.0 specifications, and using X.509 certificates to improve IDP model.
出处
《网络安全技术与应用》
2013年第8期31-32,共2页
Network Security Technology & Application
关键词
云计算
OAuth2
0规范
数字证书
identity authentication
OpenID
X.509 certificates
cloud computing