• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

基于令牌的访问控制方法增强微服务安全性。

Enhancing Microservices Security with Token-Based Access Control Method.

机构信息

Department of Computer Sciences, Kaunas University of Technology, Studentu str. 50, 51368 Kaunas, Lithuania.

出版信息

Sensors (Basel). 2023 Mar 22;23(6):3363. doi: 10.3390/s23063363.

DOI:10.3390/s23063363
PMID:36992074
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC10052058/
Abstract

Microservices are compact, independent services that work together with other microservices to support a single application function. Organizations may quickly deliver high-quality applications using the effective design pattern of the application function. Microservices allow for the alteration of one service in an application without affecting the other services. Containers and serverless functions, two cloud-native technologies, are frequently used to create microservices applications. A distributed, multi-component program has a number of advantages, but it also introduces new security risks that are not present in more conventional monolithic applications. The objective is to propose a method for access control that ensures the enhanced security of microservices. The proposed method was experimentally tested and validated in comparison to the centralized and decentralized architectures of the microservices. The obtained results showed that the proposed method enhanced the security of decentralized microservices by distributing the access control responsibility across multiple microservices within the external authentication and internal authorization processes. This allows for easy management of permissions between microservices and can help prevent unauthorized access to sensitive data and resources, as well as reduce the risk of attacks on microservices.

摘要

微服务是小型的、独立的服务,它们与其他微服务一起协作,以支持单个应用程序功能。组织可以使用应用程序功能的有效设计模式快速交付高质量的应用程序。微服务允许在不影响其他服务的情况下更改应用程序中的一个服务。容器和无服务器功能是两种常用的云原生技术,用于创建微服务应用程序。分布式、多组件程序具有许多优势,但也引入了传统单片应用程序中不存在的新安全风险。目标是提出一种访问控制方法,以确保微服务的增强安全性。所提出的方法在实验中进行了测试,并与微服务的集中式和去中心化架构进行了比较。得到的结果表明,所提出的方法通过在外部身份验证和内部授权过程中将访问控制责任分布在多个微服务中,增强了去中心化微服务的安全性。这使得在微服务之间轻松管理权限成为可能,并有助于防止对敏感数据和资源的未经授权访问,以及降低对微服务的攻击风险。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/e89434311ad5/sensors-23-03363-g010.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/17a1489e5db5/sensors-23-03363-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/070456beab0b/sensors-23-03363-g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/8856d0be8b67/sensors-23-03363-g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/19258d306ca0/sensors-23-03363-g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/0ccd4e63c2c3/sensors-23-03363-g005.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/0a3118abbb87/sensors-23-03363-g006.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/e807c45cbc9c/sensors-23-03363-g007.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/05a81d27ff1a/sensors-23-03363-g008.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/052c9cac4b00/sensors-23-03363-g009.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/e89434311ad5/sensors-23-03363-g010.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/17a1489e5db5/sensors-23-03363-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/070456beab0b/sensors-23-03363-g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/8856d0be8b67/sensors-23-03363-g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/19258d306ca0/sensors-23-03363-g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/0ccd4e63c2c3/sensors-23-03363-g005.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/0a3118abbb87/sensors-23-03363-g006.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/e807c45cbc9c/sensors-23-03363-g007.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/05a81d27ff1a/sensors-23-03363-g008.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/052c9cac4b00/sensors-23-03363-g009.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0ef3/10052058/e89434311ad5/sensors-23-03363-g010.jpg

相似文献

1
Enhancing Microservices Security with Token-Based Access Control Method.基于令牌的访问控制方法增强微服务安全性。
Sensors (Basel). 2023 Mar 22;23(6):3363. doi: 10.3390/s23063363.
2
Decentralized access control for secure microservices cooperation with blockchain.用于与区块链进行安全微服务协作的分布式访问控制。
ISA Trans. 2023 Oct;141:44-51. doi: 10.1016/j.isatra.2023.07.018. Epub 2023 Jul 20.
3
Relevant Cybersecurity Aspects of IoT Microservices Architectures Deployed over Next-Generation Mobile Networks.物联网微服务架构在下一代移动网络上部署的相关网络安全方面。
Sensors (Basel). 2022 Dec 24;23(1):189. doi: 10.3390/s23010189.
4
Microservice Security Agent Based On API Gateway in Edge Computing.基于 API 网关的边缘计算中微服务安全代理。
Sensors (Basel). 2019 Nov 10;19(22):4905. doi: 10.3390/s19224905.
5
DNS/DANE Collision-Based Distributed and Dynamic Authentication for Microservices in IoT .物联网中基于DNS/DANE冲突的微服务分布式动态认证
Sensors (Basel). 2019 Jul 26;19(15):3292. doi: 10.3390/s19153292.
6
A Blockchain-Based Authentication and Authorization Scheme for Distributed Mobile Cloud Computing Services.基于区块链的分布式移动云计算服务认证授权方案。
Sensors (Basel). 2023 Jan 22;23(3):1264. doi: 10.3390/s23031264.
7
A Microservice and Serverless Architecture for Secure IoT System.一种用于安全物联网系统的微服务和无服务器架构。
Sensors (Basel). 2023 May 18;23(10):4868. doi: 10.3390/s23104868.
8
SEMGROMI-a semantic grouping algorithm to identifying microservices using semantic similarity of user stories.SEMGROMI——一种使用用户故事语义相似度来识别微服务的语义分组算法。
PeerJ Comput Sci. 2023 May 12;9:e1380. doi: 10.7717/peerj-cs.1380. eCollection 2023.
9
Blockchain-Based Context-Aware Authorization Management as a Service in IoT.基于区块链的物联网上下文感知授权管理即服务。
Sensors (Basel). 2021 Nov 18;21(22):7656. doi: 10.3390/s21227656.
10
Model for Hosting an Application Based on Microservices in Multi-Cloud.基于微服务的多云计算应用托管模型。
Sensors (Basel). 2023 May 2;23(9):4450. doi: 10.3390/s23094450.

本文引用的文献

1
Applying Spring Security Framework with KeyCloak-Based OAuth2 to Protect Microservice Architecture APIs: A Case Study.应用基于 KeyCloak 的 OAuth2 的 Spring Security 框架来保护微服务架构 API:案例研究。
Sensors (Basel). 2022 Feb 22;22(5):1703. doi: 10.3390/s22051703.
2
Microservice Security Agent Based On API Gateway in Edge Computing.基于 API 网关的边缘计算中微服务安全代理。
Sensors (Basel). 2019 Nov 10;19(22):4905. doi: 10.3390/s19224905.
3
MicroShare: Privacy-Preserved Medical Resource Sharing through MicroService Architecture.
微分享:通过微服务架构实现隐私保护的医疗资源共享。
Int J Biol Sci. 2018 May 22;14(8):907-919. doi: 10.7150/ijbs.24617. eCollection 2018.