Authentication and authorization orchestrator for microservice-based software architectures
A. Banati, Eszter Kail, Krisztián Karóczkai, Miklós Kozlovszky · 2018
Nowadays the demand for cloud and IT services is gaining more and more popularity, therefore, the various IT solutions which implement them need to face some challenges. More and more intensive user activities require the use of well-scalable and distributed solutions which (from software technology point of view) disassembles classical monolithic architectures into microarchitectures. Consequently, instead of one or a few well-determined application-level points of access, the system must provide many points of access for the users and the other parts of the application involving many authentication and authorization processes. Moreover, the number and the location of these points of access are constantly changing during the running time implying new challenges in the security and the management field. One of the solutions is to give an encrypted token (typically implemented by a JSON Web Token) to the users after their logins which will be attached to each query. In this paper we develop an authentication and authorization orchestrator for the microservices which can manage the tokens (create and delete) needed to the authentication and authorization of the users. The orchestrator service contains a client API to provide the necessary information for the microservice in Java environment without the modification of the original application.