Interoperable OAuth 2.0 Framework
Se-Ra Oh, Young‐Gab Kim · 2019
Internet of things (IoT) is becoming key paradigm in our everyday life. However, interoperability which is essential key to share services and resources in heterogenous IoT domains is difficult to be achieved since some technologies are often designed without considering interoperability. The open authorization (OAuth) 2.0 framework used in IoT as well as conventional web environment also did not consider the interoperability in spite of its wide usage. In other words, systems cannot interoperate together without other alternatives even though they implement same OAuth 2.0 framework standard. We therefore propose IOAF (interoperable OAuth 2.0 framework). IOAF provides an additional authorization layer to support common authorization server capabilities, and supports four extended authorization grant types used to obtain IAT (interoperable access token) which has global scope in multiple domains. This paper shows the main requirements and benefits of IOAF, and describes detailed flow of authorization grant types.