Advanced OAuth Security

所在平台: Udemy

课程主页: https://www.udemy.com/course/advanced-oauth-security/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:高级OAuth安全性 课程概述:某些应用程序相较于OAuth 2.0核心规范需要更高的安全级别。本课程将带您深入了解FAPI,这是OAuth 2.0的扩展,提供了在OAuth流程中额外的安全层。本课程涵盖了OAuth工作组在IETF和OpenID基金会开发的扩展,包括:PKCE、授权服务器发行者标识符(iss)、推送授权请求(PAR)、相互TLS(MTLS)、私钥JWT、持有证明演示(DPoP)、JWT响应用于OAuth令牌检查、JWT安全授权请求(JAR)、JWT安全授权响应模式(JARM)及HTTP签名。 适合对象: - 已具备OAuth基本知识的学习者 - 希望提升知识水平的开发者 - 对保障系统安全符合行业标准有兴趣的技术人员 - 希望深入理解应用安全并成为技术领导者的个人 课程前提: - 理解HTTP请求、响应及JSON - 对JSON Web Tokens (JWT)有基本了解 - 熟悉OAuth授权码流程 课程内容分为五个部分: 1. 概述OAuth授权码流程,FAPI设定的安全目标,以及需要防护的攻击类型。 2. 专注前通道安全,讨论授权码注入攻击、PKCE、授权服务器混合攻击及使用推送授权请求。 3. 专注后通道安全,讨论相互TLS与私钥JWT在客户端认证中的区别。 4. 探讨使用相互TLS和DPoP实现持有证明(发送者限制)访问令牌。 5. 讨论如何在OAuth流程的每一环节实现不可否认性。 通过本课程,学员将能将OAuth知识提升到一个新高度,更好地保障应用安全。

课程评论(0条)

课程详情

Certain applications need a higher level of security compared to what is part of the core OAuth 2.0 specifications. This course will guide you through the details of FAPI, a set of extensions of OAuth 2.0 that provide additional layers of security throughout the OAuth flows. This course covers the extensions of OAuth developed by the OAuth Working Group at the IETF as well as the OpenID Foundation, including:PKCEAuthorization Server Issuer Identifier (iss)Pushed Authorization Requests (PAR)Mutual TLS (MTLS)Private Key JWTDemonstration of Proof of Possession (DPoP)JWT Response for OAuth Token IntrospectionJWT-Secured Authorization Requests (JAR)JWT-Secured Authorization Response Mode (JARM)HTTP SignaturesThis course is for you because...You've got a solid understanding of the basics of OAuth, andYou're looking to take your knowledge to the next levelYou want to ensure the systems you're building are up to the industry standards in securityYou want to deepen your understanding of application security and become a technical leaderPrerequisitesAn understanding of HTTP requests, responses, and JSONA basic understanding of JSON Web Tokens (JWT)Familiarity with the OAuth authorization code flowThe content is divided into five parts, beginning with and overview of the OAuth authorization code flow, an overview of the security goals set out by FAPI and related extensions, as well as a description of the types of attacks we are concerned about protecting against. Part two focuses on securing the front channel, where we'll discuss authorization code injection attacks, PKCE, authorization server mixup attacks, and using Pushed Authorization Requests. Part three focuses on the back channel, and discusses the differences between Mutual TLS and Private Key JWT for client authentication. Part four is all about proof-of-possession (sender-constraining) access tokens using Mutual TLS and DPoP. Part five discusses how to achieve non-repudiation throughout each leg of the OAuth flow.

课程标签

0人关注该课程

主题相关的课程