12.2. Informative References (资料性参考文献)
12.2. Informative References (资料性参考文献)
[BASIN]
Basin, D., Cremers, C., and S. Meier, "Provably Repairing the ISO/IEC 9798 Standard for Entity Authentication" (可证明地修复用于实体认证的 ISO/IEC 9798 标准), Journal of Computer Security - Security and Trust Principles, Volume 21, Issue 6, pp. 817-846, November 2013, https://www.cs.ox.ac.uk/people/cas.cremers/downloads/papers/BCM2012-iso9798.pdf.
中文说明: 分析并修复 ISO/IEC 9798 实体认证标准中的安全问题.
[CapURLs]
Tennison, J., Ed., "Good Practices for Capability URLs" (Capability URLs 良好实践), W3C First Public Working Draft, 18 February 2014, https://www.w3.org/TR/capability-urls/.
中文说明: 给出 Capability URL 的设计和使用实践.
[IANA.JWT.Claims]
IANA, "JSON Web Token (JWT)" (JSON Web Token (JWT) 注册表), https://www.iana.org/assignments/jwt.
中文说明: IANA 维护的 JWT 相关注册表.
[IANA.MediaTypes]
IANA, "Media Types" (媒体类型注册表), https://www.iana.org/assignments/media-types.
中文说明: IANA 维护的 Media Types 注册表.
[IANA.OAuth.Parameters]
IANA, "OAuth Parameters" (OAuth 参数注册表), https://www.iana.org/assignments/oauth-parameters.
中文说明: IANA 维护的 OAuth Parameters 注册表.
[OpenID.Core]
Sakimura, N., Bradley, J., Jones, M.B., de Medeiros, B., and C. Mortimore, "OpenID Connect Core 1.0 incorporating errata set 1" (合并勘误集 1 的 OpenID Connect Core 1.0), OpenID Foundation Standards, 8 November 2014, http://openid.net/specs/openid-connect-core-1_0.html.
中文说明: 定义 OpenID Connect Core 1.0 的核心认证协议.
[RFC2046]
Freed, N. and N. Borenstein, "Multipurpose Internet Mail Extensions (MIME) Part Two: Media Types" (多用途互联网邮件扩展 (MIME) 第二部分: 媒体类型), RFC 2046, DOI 10.17487/RFC2046, November 1996, https://www.rfc-editor.org/info/rfc2046.
中文说明: 定义 MIME 媒体类型体系.
[RFC6819]
Lodderstedt, T., Ed., McGloin, M., and P. Hunt, "OAuth 2.0 Threat Model and Security Considerations" (OAuth 2.0 威胁模型和安全考量), RFC 6819, DOI 10.17487/RFC6819, January 2013, https://www.rfc-editor.org/info/rfc6819.
中文说明: 描述 OAuth 2.0 的威胁模型和安全缓解措施.
[RFC6838]
Freed, N., Klensin, J., and T. Hansen, "Media Type Specifications and Registration Procedures" (媒体类型规范和注册流程), BCP 13, RFC 6838, DOI 10.17487/RFC6838, January 2013, https://www.rfc-editor.org/info/rfc6838.
中文说明: 定义媒体类型规范编写和 IANA 注册流程.
[RFC6973]
Cooper, A., Tschofenig, H., Aboba, B., Peterson, J., Morris, J., Hansen, M., and R. Smith, "Privacy Considerations for Internet Protocols" (互联网协议的隐私考量), RFC 6973, DOI 10.17487/RFC6973, July 2013, https://www.rfc-editor.org/info/rfc6973.
中文说明: 给出互联网协议设计中的隐私评估框架.
[RFC7523]
Jones, M., Campbell, B., and C. Mortimore, "JSON Web Token (JWT) Profile for OAuth 2.0 Client Authentication and Authorization Grants" (用于 OAuth 2.0 客户端认证和授权授予的 JSON Web Token (JWT) Profile), RFC 7523, DOI 10.17487/RFC7523, May 2015, https://www.rfc-editor.org/info/rfc7523.
中文说明: 定义 JWT 在 OAuth 2.0 客户端认证和授权授予中的 Profile.
[RFC7591]
Richer, J., Ed., Jones, M., Bradley, J., Machulak, M., and P. Hunt, "OAuth 2.0 Dynamic Client Registration Protocol" (OAuth 2.0 动态客户端注册协议), RFC 7591, DOI 10.17487/RFC7591, July 2015, https://www.rfc-editor.org/info/rfc7591.
中文说明: 定义 OAuth 2.0 客户端动态注册协议.
[RFC8725]
Sheffer, Y., Hardt, D., and M. Jones, "JSON Web Token Best Current Practices" (JSON Web Token 最佳当前实践), BCP 225, RFC 8725, DOI 10.17487/RFC8725, February 2020, https://www.rfc-editor.org/info/rfc8725.
中文说明: 给出 JWT 安全使用的最佳当前实践.