Decentralized authorization framework for untrusted heterogeneous client devices비신뢰 이기종 클라이언트 기기를 위한 분권화된 인가 프레임워크

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 125
  • Download : 0
These days, network-connected computing devices such as various smart/IoT devices, laptops, and smartphones are becoming more popular due to the rapid evolution of mobile computing technologies. Also, as the number of devices around a single user increases, one device usually does not exclusively belong to a single user anymore. However, this multi-device paradigm makes the access delegation toward such devices much more difficult. If permission is delegated to other devices, they typically cannot be managed adequately and precisely as the user's original intention. This is mainly because 1) the original design of access delegation protocol tends to be coarse-grained, 2) every device has a unique hardware/software stack which is hard to validate its security status in detail precisely, and 3) device owners can even share their devices among other multiple users so the original device owner cannot fully trust its behavior when shared with other people. This thesis introduces DAuth, an OAuth 2.0 extension suitable for access delegation in the multi-device environment. It specifies and enforces the security policy for OAuth 2.0 bearer tokens so that any token in the multi-device environment cannot be utilized by malicious misuses. DAuth extends the current OAuth 2.0 device grant by separating a single OAuth request-response structure into two subparts. Our evaluation shows that adopting DAuth to existing OAuth 2.0 implementation requires little engineering effort, and it adds only an affordable overhead in end-to-end latency.
Advisors
Shin, Insikresearcher신인식researcher
Description
한국과학기술원 :정보보호대학원,
Publisher
한국과학기술원
Issue Date
2022
Identifier
325007
Language
eng
Description

학위논문(석사) - 한국과학기술원 : 정보보호대학원, 2022.2,[iii, 31 p. :]

URI
http://hdl.handle.net/10203/309622
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=997743&flag=dissertation
Appears in Collection
IS-Theses_Master(석사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0