ENGLISH

Authorization and Access Control: Foundations, Frameworks, and Applications

Book information

Publisher
CRC Press
Year
2022
ISBN
103221452X, 9781032214528
Language
english
Format
PDF
Filesize
4 MB (3977358 bytes)
Pages
85\87
Topic
Computers Security
Time added
2022-10-23 23:55:08

Description

This book focuses on various authorization and access control techniques, threats and attack modeling, including an overview of the Open Authorization 2.0 (OAuth 2.0) framework along with user-managed access (UMA) and security analysis. Important key concepts are discussed regarding login credentials with restricted access to third parties with a primary account as a resource server. A detailed protocol overview and authorization process, along with security analysis of OAuth 2.0, are also discussed in the book. Case studies of websites with vulnerability issues are included. FEATURES Provides an overview of the security challenges of IoT and mitigation techniques with a focus on authorization and access control mechanisms Discusses a behavioral analysis of threats and attacks using UML base modeling Covers the use of the OAuth 2.0 Protocol and UMA for connecting web applications Includes role-based access control (RBAC), discretionary access control (DAC), mandatory access control (MAC) and permission-based access control (PBAC) Explores how to provide access to third-party web applications through a resource server by use of a secured and reliable OAuth 2.0 framework This book is for researchers and professionals who are engaged in IT security, auditing and computer engineering. Cover Half Title Title Page Copyright Page Table of Contents Preface Authors 1 Introduction 1.1 Internet to Internet of Things 1.2 ICT Standardization 1.3 Convergence 1.4 Industry 4.0 Standards 1.5 Security Issues and Challenges 1.6 Summary References 2 Authorization and Access Control 2.1 Introduction 2.2 Threats and Attacks Modeling 2.3 Overview of Authentication and Authorization 2.4 Access Control Paradigms 2.5 Implementation Perspective 2.6 Summary References 3 Open Authorization 2.0 3.1 Introduction 3.1.1 OAuth Roles/Main Actors of OAuth2.0 3.2 Motivation 3.3 Protocol Overview 3.4 Use Case 3.4.1 User Agent as Use Case 3.4.1.1 Educational Application 3.4.2 Web Server in Web Application 3.5 Authorization Process 3.5.1 Authorization Code Grant 3.5.1.1 Authorization Code 3.5.2 Implicit Grant 3.5.3 Resource Owner Password Credential Grant 3.5.4 Client Credentials Grant 3.5.4.1 Types of Token 3.6 Security Analysis 3.6.1 Phishing Attacks 3.6.2 Countermeasures 3.6.3 Clickjacking 3.7 Summary References 4 User-Managed Access 4.1 Introduction 4.1.1 Roles of UMA Protocol 4.1.1.1 Resource Owner 4.1.1.2 Client Application 4.1.1.3 Authorization Server 4.1.1.4 Resource Server 4.1.1.5 Requesting Party 4.2 Motivation 4.3 Protocol Overview 4.4 Use Cases 4.4.1 Healthcare Application 4.4.2 Personal Loan Approval Scenario 4.5 Authorization Process 4.5.1 Claim Collection 4.5.2 Authorization Result Determination 4.6 Security Analysis 4.6.1 PCT and RPT Vulnerability 4.6.2 Cross-Site Request Forgery Attack (CSRF) 4.7 Summary References 5 Conclusions Index

Similar books