Difference between revisions of "Sender Constrained Token"

From MgmtWiki
Jump to: navigation, search
(Created page with "==Full Title or Meme== A Sender Constrained Token can be considered to be a token there the Subject presenting the token can prove possession of some credential that i...")
 
Line 4: Line 4:
 
* [[Bearer Token]]s have proven to be susceptible to reuse by unauthorized parties.
 
* [[Bearer Token]]s have proven to be susceptible to reuse by unauthorized parties.
 
==Problems==
 
==Problems==
 +
* [[Bearer Token]]s have proven to be susceptible to reuse by unauthorized parties.
 +
 
==Solutions==
 
==Solutions==
 +
* Add a cryptographic binding between the token a some credential that is known to be in the secured possession of the [[Subject]]]
 
==References==
 
==References==
  
 
[[Category:Authorization]]
 
[[Category:Authorization]]

Revision as of 12:46, 18 December 2019

Full Title or Meme

A Sender Constrained Token can be considered to be a token there the Subject presenting the token can prove possession of some credential that is bound to the token.

Context

  • Bearer Tokens have proven to be susceptible to reuse by unauthorized parties.

Problems

  • Bearer Tokens have proven to be susceptible to reuse by unauthorized parties.

Solutions

  • Add a cryptographic binding between the token a some credential that is known to be in the secured possession of the Subject]

References