期刊文献+

基于Request Body的Open API安全认证机制 被引量:2

Open API Security Authentication Mechanism Based on Request Body
下载PDF
导出
摘要 为解决当前Open API面临的身份伪造钓鱼攻击、账户与业务信息泄露和API平台恶意攻击等问题,提出了一种基于Request Body(请求体)的API安全认证机制。该机制由双重签名验证、请求体加密、URI验证、接口权限认证和异常侦测五部分组成,用于防范钓鱼网站诱骗、加固用户数据传输安全和提升API平台抵御攻击的能力。通过在线测试和实际项目验证,表明该机制能够在保证API认证速度的同时保证用户和接口的安全。 Aiming at the problems of identity forgery phishing attacks, account and business information leakage and API platform malicious attacks, an API security authentication mechanism based on Request Body was proposed. The mechanism consists of five parts: double signature verification, request body encryption, URI verification, interface authority authentication and exception detection. It is used to prevent phishing scams, strengthen user data transmission security and improve the ability of the API platform to resist attacks. Through online testing and actual project verification, it shows that the mechanism can ensure the security of users and interfaces while ensuring the speed of API authentication.
作者 姜建武 胡垚 李景文 JIANG Jian-wu;HU Yao;LI Jing-wen(College of Geomatics and Geoinformation,Guilin University of Technology,Guilin 541004,China)
出处 《科学技术与工程》 北大核心 2019年第19期196-200,共5页 Science Technology and Engineering
基金 国家自然科学基金(41461085) 桂林市科学技术局项目(20170220) 广西测绘局项目(2018-B-02)资助
关键词 Open API 安全认证 RESTFUL API 信息加密 open API security certification restful API inforrmation encryption
  • 相关文献

参考文献8

二级参考文献38

  • 1http://aws.amazon.com/cn/s3/.
  • 2https://www.icloud.com/.
  • 3http://yun.baidu.com/?ref=ppzq.
  • 4http://www.windowsazure.cn/?fb=002.
  • 5http://www.ksyun.com/.
  • 6http://www.iimedia.cn/38351.html.
  • 7http://popcrush.com/apple-releases-statement-icloud-celeb-photo-hacks.
  • 8De Capitani di Vimercati S, Foresti S, Jajodia S, Paraboschi S, Samarati P. Over-Encryption: Management of access control evolution on outsourced data. In: Wolfgang K, ed. Proc. of the 33rd Int'l Conf. on Very Large Data Bases. Vienna: VLDB Endowment, 2007. 123-134.
  • 9De Capitani di Vimercati S, Foresti S, Jajodia S, Paraboschi S, Samarati P. Encryption policies for regulating access to outsourced data. ACM Trans. on Database Systems, 2010, 35 (2) :12. [doi:10.1145/1735886.1735891]].
  • 10De Capitani di Vimercati S,Foresti S, Jajodia S, Paraboschi S, Pelosi G, Samarati P. Preserving confidentiality of security policies in data outsourcing. In: AtluriV, ed. Proc. of the 7th ACM Workshop on Privacy in the Electronic Society. New York: ACM, 2008. 75-84. [doi:10.1145/1456403.1456417].

共引文献39

同被引文献25

引证文献2

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部