8. 参考文献 (References)
本节列出本文档引用的规范性和信息性参考文献. 为保持引用可核验性, 文献条目的作者姓名, 英文题名, 出版物名称, RFC 编号, DOI, URL 和日期等元数据按原文保留. 中文说明用于标明这些条目是协议规范, 标准文档, 实现资料或背景资料, 读者可据此追溯原始来源.
8.1 规范性参考文献 (Normative References)
以下文献构成本规范实现和解释所依赖的规范性基础.
[BCP195] : Sheffer, Y., Holz, R., and P. Saint-Andre, "Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)", BCP 195, RFC 7525, May 2015, ````http://www.rfc-editor.org/info/bcp195\````.
[RFC20] : Cerf, V., "ASCII format for network interchange", STD 80, RFC 20, DOI 10.17487/RFC0020, October 1969, ````http://www.rfc-editor.org/info/rfc20\````.
[RFC2119] : Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, DOI 10.17487/RFC2119, March 1997, ````http://www.rfc-editor.org/info/rfc2119\````.
[RFC3986] : Berners-Lee, T., Fielding, R., and L. Masinter, "Uniform Resource Identifier (URI): Generic Syntax", STD 66, RFC 3986, DOI 10.17487/RFC3986, January 2005, ````http://www.rfc-editor.org/info/rfc3986\````.
[RFC4648] : Josefsson, S., "The Base16, Base32, and Base64 Data Encodings", RFC 4648, DOI 10.17487/RFC4648, October 2006, ````http://www.rfc-editor.org/info/rfc4648\````.
[RFC5226] : Narten, T. and H. Alvestrand, "Guidelines for Writing an IANA Considerations Section in RFCs", BCP 26, RFC 5226, DOI 10.17487/RFC5226, May 2008, ````http://www.rfc-editor.org/info/rfc5226\````.
[RFC5234] : Crocker, D., Ed. and P. Overell, "Augmented BNF for Syntax Specifications: ABNF", STD 68, RFC 5234, DOI 10.17487/RFC5234, January 2008, ````http://www.rfc-editor.org/info/rfc5234\````.
[RFC6234] : Eastlake 3rd, D. and T. Hansen, "US Secure Hash Algorithms (SHA and SHA-based HMAC and HKDF)", RFC 6234, DOI 10.17487/RFC6234, May 2011, ````http://www.rfc-editor.org/info/rfc6234\````.
[RFC6749] : Hardt, D., Ed., "The OAuth 2.0 Authorization Framework", RFC 6749, DOI 10.17487/RFC6749, October 2012, ````http://www.rfc-editor.org/info/rfc6749\````.
8.2 信息性参考文献 (Informative References)
以下资料提供 OAuth 2.0 威胁模型和安全分析背景.
[RFC6819] : Lodderstedt, T., Ed., McGloin, M., and P. Hunt, "OAuth 2.0 Threat Model and Security Considerations", RFC 6819, DOI 10.17487/RFC6819, January 2013, ````http://www.rfc-editor.org/info/rfc6819\````.