摘要
Cookies是由Web服务器生成并存贮于用户计算机硬盘或内存中的文本信息,是实现Web应用认证的主要手段。分析了基于Cookie的认证机制的实现过程与特点,在此基础上指出了该认证机制易遭受的安全威胁,并提出了抵御这些威胁的安全需求。最后讨论了实现安全Cookie认证的具体方法与措施。
Cookies are text messages generated by web servers and stored in user' s hard driver or RAM, and are the primary means for web application authentication. In this paper, the implementation process and characteristics of cookie-based authentication mechanism are analyzed. The security threats to cookie-based authentication mechanism are pointed out, and the security requirements are proposed. Finally, the specific solutions for implementing secure cookie authentication are discussed.
出处
《通信技术》
2009年第6期132-134,137,共4页
Communications Technology
关键词
COOKIE
认证
访问令牌
安全套接层
Cookie: authentication
access Token: Secure Socket Layer (SSL)