首页> 外文会议>2018 International Conference on Advances in Computing, Communication Control and Networking >Pragmatic approach using OAuth mechanism for IoT device authorization in cloud
【24h】

Pragmatic approach using OAuth mechanism for IoT device authorization in cloud

机译:使用OAuth机制在云中进行IoT设备授权的实用方法

获取原文
获取原文并翻译 | 示例

摘要

To address the problem of authorization that enables a third-party service to access a resource server in a secured manner (a token based authorization without exposing user id and password), there has been research called OAuth framework. The OAuth framework gives permission for restricted access to a third party entity in a token based access control mechanism. This framework is widely used as a de-facto standard. The companies such as Google, Facebook, LinkedIn, and Microsoft are using the OAuth mechanism to enable third-party services to access their resources in a secured manner. However, the OAuth mechanism is operating on HTTP(HyperText Transfer Protocol) that assumes a server in the cloud, which adapts the OAuth mechanism, will primarily operates using HTTP. The de-facto standard protocol used by IoT(Internet of Things) devices is CoAP(Constrained Application Protocol) that is designed to be used by a simple, in other word limited, device. In the case of IoT cloud that interconnects IoT devices and related applications mainly use CoAP over TCP(Transmission Control Protocol). This paper describes the development of a pragmatic approach to authorize an application accessing IoT devices using CoAP and inter-working with already deployed HTTP based authorization servers using OAuth mechanism. The developed architecture using the proposed approach has been evaluated using the real-world device, i.e. Samsung air conditioner, with Samsung, Facebook and Github accounts. This work has become the open source IoT cloud reference implementation of OCF (Open Connectivity Foundation).
机译:为了解决使第三方服务能够以安全方式访问资源服务器的授权问题(基于令牌的授权而不暴露用户ID和密码),已经进行了研究,称为OAuth框架。 OAuth框架在基于令牌的访问控制机制中授予对第三方实体的受限访问权限。该框架被广泛用作事实上的标准。诸如Google,Facebook,LinkedIn和Microsoft之类的公司正在使用OAuth机制来使第三方服务能够以安全的方式访问其资源。但是,OAuth机制在HTTP(超文本传输​​协议)上运行,该网络假定采用OAuth机制的云中的服务器将主要使用HTTP进行操作。物联网(IoT)设备使用的事实上的标准协议是CoAP(受约束的应用协议),旨在供简单的设备(换句话说就是受限制的设备)使用。在将物联网设备和相关应用程序互连的物联网云中,主要使用基于TCP(传输控制协议)的CoAP。本文描述了一种实用方法的开发,该方法授权使用CoAP访问IoT设备的应用程序授权,并使用OAuth机制与已部署的基于HTTP的授权服务器进行互通。使用拟议方法开发的架构已通过具有三星,Facebook和Github帐户的真实设备即三星空调进行了评估。这项工作已成为OCF(开放连接基金会)的开源物联网云参考实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号