Authorization and Access Control: Foundations, Frameworks, and Applications
Book information
Description
This book focuses on various authorization and access control techniques, threats and attack modeling, including an overview of the Open Authorization 2.0 (OAuth 2.0) framework along with user-managed access (UMA) and security analysis. Important key concepts are discussed regarding login credentials with restricted access to third parties with a primary account as a resource server. A detailed protocol overview and authorization process, along with security analysis of OAuth 2.0, are also discussed in the book. Case studies of websites with vulnerability issues are included. FEATURES Provides an overview of the security challenges of IoT and mitigation techniques with a focus on authorization and access control mechanisms Discusses a behavioral analysis of threats and attacks using UML base modeling Covers the use of the OAuth 2.0 Protocol and UMA for connecting web applications Includes role-based access control (RBAC), discretionary access control (DAC), mandatory access control (MAC) and permission-based access control (PBAC) Explores how to provide access to third-party web applications through a resource server by use of a secured and reliable OAuth 2.0 framework This book is for researchers and professionals who are engaged in IT security, auditing and computer engineering. Cover Half Title Title Page Copyright Page Table of Contents Preface Authors 1 Introduction 1.1 Internet to Internet of Things 1.2 ICT Standardization 1.3 Convergence 1.4 Industry 4.0 Standards 1.5 Security Issues and Challenges 1.6 Summary References 2 Authorization and Access Control 2.1 Introduction 2.2 Threats and Attacks Modeling 2.3 Overview of Authentication and Authorization 2.4 Access Control Paradigms 2.5 Implementation Perspective 2.6 Summary References 3 Open Authorization 2.0 3.1 Introduction 3.1.1 OAuth Roles/Main Actors of OAuth2.0 3.2 Motivation 3.3 Protocol Overview 3.4 Use Case 3.4.1 User Agent as Use Case 3.4.1.1 Educational Application 3.4.2 Web Server in Web Application 3.5 Authorization Process 3.5.1 Authorization Code Grant 3.5.1.1 Authorization Code 3.5.2 Implicit Grant 3.5.3 Resource Owner Password Credential Grant 3.5.4 Client Credentials Grant 3.5.4.1 Types of Token 3.6 Security Analysis 3.6.1 Phishing Attacks 3.6.2 Countermeasures 3.6.3 Clickjacking 3.7 Summary References 4 User-Managed Access 4.1 Introduction 4.1.1 Roles of UMA Protocol 4.1.1.1 Resource Owner 4.1.1.2 Client Application 4.1.1.3 Authorization Server 4.1.1.4 Resource Server 4.1.1.5 Requesting Party 4.2 Motivation 4.3 Protocol Overview 4.4 Use Cases 4.4.1 Healthcare Application 4.4.2 Personal Loan Approval Scenario 4.5 Authorization Process 4.5.1 Claim Collection 4.5.2 Authorization Result Determination 4.6 Security Analysis 4.6.1 PCT and RPT Vulnerability 4.6.2 Cross-Site Request Forgery Attack (CSRF) 4.7 Summary References 5 Conclusions Index
Similar books
The Underwater World for Digital Data Transmission (SpringerBriefs in Applied Sciences and Technology)
2021 · PDF
Data Centric Artificial Intelligence: A Beginner’s Guide (Data-Intensive Research)
2023 · PDF
VANET: Challenges and Opportunities
2021 · PDF
Predictive Analytics for Mechanical Engineering: A Beginners Guide (SpringerBriefs in Applied Sciences and Technology)
2023 · PDF
Data-Centric Artificial Intelligence for Multidisciplinary Applications
2024 · PDF
Foundations of Data Science Based Healthcare Internet of Things (SpringerBriefs in Applied Sciences and Technology)
2021 · PDF
Disruptive Developments in Biomedical Applications
2023 · PDF
Artificial Intelligence in Information and Communication Technologies, Healthcare and Education: A Roadmap Ahead
2022 · PDF