OAuth Standard for User Authorization of Cloud Services
Piotr K. Tysowski · 2016
The IETF OAuth specification is an open Web standard that enables secure authorization for applications running on various kinds of platforms. Using OAuth, third-party client applications may access protected resources on the cloud or elsewhere without the resource owner being required to supply user credentials such as an identity and password. In order to achieve authorization, OAuth specifies the use of a token that enables validated access to a resource. OAuth can effectively be combined with an identity-management system such as OpenID to concurrently provide both authorization and authentication functions. The original version 1.0 of the OAuth protocol relied upon the exchange of client-side signatures, while the new version 2.0 relies upon a bearer token scheme. The new protocol is designed to be simpler to implement and supports new application contexts, but introduces its own new challenges.