Difference between revisions of "Sender Constrained Token"
From MgmtWiki
(Created page with "==Full Title or Meme== A Sender Constrained Token can be considered to be a token there the Subject presenting the token can prove possession of some credential that i...") |
|||
| Line 4: | Line 4: | ||
* [[Bearer Token]]s have proven to be susceptible to reuse by unauthorized parties. | * [[Bearer Token]]s have proven to be susceptible to reuse by unauthorized parties. | ||
==Problems== | ==Problems== | ||
| + | * [[Bearer Token]]s have proven to be susceptible to reuse by unauthorized parties. | ||
| + | |||
==Solutions== | ==Solutions== | ||
| + | * Add a cryptographic binding between the token a some credential that is known to be in the secured possession of the [[Subject]]] | ||
==References== | ==References== | ||
[[Category:Authorization]] | [[Category:Authorization]] | ||
Revision as of 12:46, 18 December 2019
Full Title or Meme
A Sender Constrained Token can be considered to be a token there the Subject presenting the token can prove possession of some credential that is bound to the token.
Context
- Bearer Tokens have proven to be susceptible to reuse by unauthorized parties.
Problems
- Bearer Tokens have proven to be susceptible to reuse by unauthorized parties.
Solutions
- Add a cryptographic binding between the token a some credential that is known to be in the secured possession of the Subject]