Strong Identity Authentication Scheme Based on Password Signature and OAuth2.0 Protocol
Author:
Affiliation:

Clc Number:

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    In order to solve the identity authentication problem of network applications, the OAuth2.0 protocol has been widely used in the actual production environment. However, many systems use the OAuth2.0 standard unreasonably in their design, which results in many security flaws. This study analyzes the security problems of OAuth2.0 protocol in recent years, including the man-in-the-middle attack, authorization hijacking vulnerability, and CSRF vulnerability, and the study proposes a password-based Schnorr digital signature and OAuth2.0 strong identity authentication scheme for solving these security problems. Finally, the security of the scheme is analyzed. The results show that the scheme has excellent security and is easy to use.

    Reference
    Related
    Cited by
Get Citation

郝恬,左黎明,陈艺琳.基于口令签名和OAuth2.0协议的强身份认证方案.计算机系统应用,2023,32(4):347-353

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:August 06,2022
  • Revised:September 07,2022
  • Adopted:
  • Online: December 23,2022
  • Published:
You are the firstVisitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-3
Address:4# South Fourth Street, Zhongguancun,Haidian, Beijing,Postal Code:100190
Phone:010-62661041 Fax: Email:csa (a) iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063