Download presentation
Presentation is loading. Please wait.
1
Hannes Tschofenig (IETF#79, SAAG, Beijing)
2
Acknowledgements I would like to thank to Pasi Eronen. I am re- using some of his slides in this presentation. 6/1/2015IETF #79, OAuth Overview, SAAG Meeting, Beijing 2
3
6/1/2015IETF #79, OAuth Overview, SAAG Meeting, Beijing 3 The Problem: Secure Data Sharing
4
6/1/2015IETF #79, OAuth Overview, SAAG Meeting, Beijing 4
5
6/1/2015IETF #79, OAuth Overview, SAAG Meeting, Beijing 5 Example OAuth Exchange
6
6/1/20156IETF #79, OAuth Overview, SAAG Meeting, Beijing User Enters a URL In the web browser
7
6/1/20157IETF #79, OAuth Overview, SAAG Meeting, Beijing Browser opens URL
8
6/1/20158IETF #79, OAuth Overview, SAAG Meeting, Beijing User is presented With the option to access remote (but protected) data
9
6/1/20159IETF #79, OAuth Overview, SAAG Meeting, Beijing Resource Consumer Redirects to Authorization Server
10
6/1/201510IETF #79, OAuth Overview, SAAG Meeting, Beijing User authentication takes place
11
6/1/201511IETF #79, OAuth Overview, SAAG Meeting, Beijing User authorizes data exchange
12
6/1/201512IETF #79, OAuth Overview, SAAG Meeting, Beijing Authorization Granted Redirect from Authz Server back to Resource Consumer
13
6/1/201513IETF #79, OAuth Overview, SAAG Meeting, Beijing Resource Consumer Requests Token from Authorization Server For Access to the Resource Server
14
6/1/201514IETF #79, OAuth Overview, SAAG Meeting, Beijing Resource Consumer Receives Token
15
6/1/201515IETF #79, OAuth Overview, SAAG Meeting, Beijing Resource Consumer Requests access to Data at the Resource Server
16
6/1/201516IETF #79, OAuth Overview, SAAG Meeting, Beijing Data exchange takes place
17
OAuth Profiles Token Request Work Scope User User Agent Authorization Server Resource Server Resource Consumer Access Request (incl. Token) Authorization Request 6/1/201517IETF #79, OAuth Overview, SAAG Meeting, Beijing User Interface Token Format And Content Authz Server Interaction Data ExchangeAuthentication Request Security Token Request/ Response Exchange
18
Summary Open Web Authentication (OAuth) is developed in the IETF to provide delegated authentication. Code available (see http://oauth.net/code/) and deployment on the way.http://oauth.net/code/ Working group is working on finalizing the OAuth 2.0 specification: –http://tools.ietf.org/html/draft-ietf-oauth-v2http://tools.ietf.org/html/draft-ietf-oauth-v2 Rechartering discussion started with many extensions being considered by the group Your input is needed! 6/1/2015IETF #79, OAuth Overview, SAAG Meeting, Beijing 18
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.