Implementation of Permission Management Framework Based on Token through Shiro

Shulin Yang, Jieping Hu, Shaopeng Wang, Cai Hongwei · 2017 International Conference on Computer Technology, Electronics and Communication (ICCTEC) · 2017

Traditional permission management based on Session has many problems, such as high memory cost, unsuitable for mobile application, and not convenient for cross domain resource sharing. The permission management based on Token can solve the above problems better. Through the analysis of Token authentication process and the research of Apache Shiro architecture, a set of universal and easy access control model based on RBAC (Role-Based Access Control) is designed. JWT (JSON Web Token) is integrated and a security authentication framework based on Token is implemented. The practical application shows that the security authentication framework is flexible, which is easy to expand and transplant.

Read the paper · More papers on PaperTik