跳到主要内容

12.2. Informative References (资料性参考文献)

12.2. Informative References (资料性参考文献)

[BASIN]

Basin, D., Cremers, C., and S. Meier, "Provably Repairing the ISO/IEC 9798 Standard for Entity Authentication" (可证明地修复用于实体认证的 ISO/IEC 9798 标准), Journal of Computer Security - Security and Trust Principles, Volume 21, Issue 6, pp. 817-846, November 2013, https://www.cs.ox.ac.uk/people/cas.cremers/downloads/papers/BCM2012-iso9798.pdf.

中文说明: 分析并修复 ISO/IEC 9798 实体认证标准中的安全问题.

[CapURLs]

Tennison, J., Ed., "Good Practices for Capability URLs" (Capability URLs 良好实践), W3C First Public Working Draft, 18 February 2014, https://www.w3.org/TR/capability-urls/.

中文说明: 给出 Capability URL 的设计和使用实践.

[IANA.JWT.Claims]

IANA, "JSON Web Token (JWT)" (JSON Web Token (JWT) 注册表), https://www.iana.org/assignments/jwt.

中文说明: IANA 维护的 JWT 相关注册表.

[IANA.MediaTypes]

IANA, "Media Types" (媒体类型注册表), https://www.iana.org/assignments/media-types.

中文说明: IANA 维护的 Media Types 注册表.

[IANA.OAuth.Parameters]

IANA, "OAuth Parameters" (OAuth 参数注册表), https://www.iana.org/assignments/oauth-parameters.

中文说明: IANA 维护的 OAuth Parameters 注册表.

[OpenID.Core]

Sakimura, N., Bradley, J., Jones, M.B., de Medeiros, B., and C. Mortimore, "OpenID Connect Core 1.0 incorporating errata set 1" (合并勘误集 1 的 OpenID Connect Core 1.0), OpenID Foundation Standards, 8 November 2014, http://openid.net/specs/openid-connect-core-1_0.html.

中文说明: 定义 OpenID Connect Core 1.0 的核心认证协议.

[RFC2046]

Freed, N. and N. Borenstein, "Multipurpose Internet Mail Extensions (MIME) Part Two: Media Types" (多用途互联网邮件扩展 (MIME) 第二部分: 媒体类型), RFC 2046, DOI 10.17487/RFC2046, November 1996, https://www.rfc-editor.org/info/rfc2046.

中文说明: 定义 MIME 媒体类型体系.

[RFC6819]

Lodderstedt, T., Ed., McGloin, M., and P. Hunt, "OAuth 2.0 Threat Model and Security Considerations" (OAuth 2.0 威胁模型和安全考量), RFC 6819, DOI 10.17487/RFC6819, January 2013, https://www.rfc-editor.org/info/rfc6819.

中文说明: 描述 OAuth 2.0 的威胁模型和安全缓解措施.

[RFC6838]

Freed, N., Klensin, J., and T. Hansen, "Media Type Specifications and Registration Procedures" (媒体类型规范和注册流程), BCP 13, RFC 6838, DOI 10.17487/RFC6838, January 2013, https://www.rfc-editor.org/info/rfc6838.

中文说明: 定义媒体类型规范编写和 IANA 注册流程.

[RFC6973]

Cooper, A., Tschofenig, H., Aboba, B., Peterson, J., Morris, J., Hansen, M., and R. Smith, "Privacy Considerations for Internet Protocols" (互联网协议的隐私考量), RFC 6973, DOI 10.17487/RFC6973, July 2013, https://www.rfc-editor.org/info/rfc6973.

中文说明: 给出互联网协议设计中的隐私评估框架.

[RFC7523]

Jones, M., Campbell, B., and C. Mortimore, "JSON Web Token (JWT) Profile for OAuth 2.0 Client Authentication and Authorization Grants" (用于 OAuth 2.0 客户端认证和授权授予的 JSON Web Token (JWT) Profile), RFC 7523, DOI 10.17487/RFC7523, May 2015, https://www.rfc-editor.org/info/rfc7523.

中文说明: 定义 JWT 在 OAuth 2.0 客户端认证和授权授予中的 Profile.

[RFC7591]

Richer, J., Ed., Jones, M., Bradley, J., Machulak, M., and P. Hunt, "OAuth 2.0 Dynamic Client Registration Protocol" (OAuth 2.0 动态客户端注册协议), RFC 7591, DOI 10.17487/RFC7591, July 2015, https://www.rfc-editor.org/info/rfc7591.

中文说明: 定义 OAuth 2.0 客户端动态注册协议.

[RFC8725]

Sheffer, Y., Hardt, D., and M. Jones, "JSON Web Token Best Current Practices" (JSON Web Token 最佳当前实践), BCP 225, RFC 8725, DOI 10.17487/RFC8725, February 2020, https://www.rfc-editor.org/info/rfc8725.

中文说明: 给出 JWT 安全使用的最佳当前实践.