An Extended Content Authorization Mechanism in Web Mashup

碩士 === 輔仁大學 === 資訊工程學系 === 98 === In the Web 2.0 Environment, user contents are aggregated through mashup. To ensure the security and privacy of the aggregated contents is an importance issue for service providers. With the OAuth support, content provider and content consumer could retrieve the cont...

Full description

Bibliographic Details
Main Authors: SAM CHI HOU, 岑志豪
Other Authors: Mei Hsing
Format: Others
Language:zh-TW
Published: 2010
Online Access:http://ndltd.ncl.edu.tw/handle/78965396786799721249
id ndltd-TW-098FJU00392009
record_format oai_dc
spelling ndltd-TW-098FJU003920092016-04-25T04:29:24Z http://ndltd.ncl.edu.tw/handle/78965396786799721249 An Extended Content Authorization Mechanism in Web Mashup 一個於網際混搭環境中的擴充內容授權機制 SAM CHI HOU 岑志豪 碩士 輔仁大學 資訊工程學系 98 In the Web 2.0 Environment, user contents are aggregated through mashup. To ensure the security and privacy of the aggregated contents is an importance issue for service providers. With the OAuth support, content provider and content consumer could retrieve the content under owner’s approval. But OAuth does not deal with the following three relations at present: the relation between content owner and users; the relation between different content providers; and the relation between aggregated contents and the content users. The authorization server (AS) can be independent from the content provider services under OAuth 2.0. Content providers deploy the authorization rules on AS, and then AS could have more rooms for consideration in authorization decisions. AS could export authorization rules to other services. The consumer could make a decision while it shares the aggregated contents to other service according to the authorization rule that AS provided. In this thesis, we implement an AS prototype, and design the data structure of the authorization rule which is convenience for other services to deploy. This research analyze the relations about the content; associate the authorization rules from the content providers; identify the authorization conflict; notify the content owner, and make a decision when the contents are shared to other users. We made a mashup among Facebook, Google Health and Social Health Space, and implemented an AS prototype to verify the feasibility of the proposed mechanism. Mei Hsing 梅興 2010 學位論文 ; thesis 31 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 輔仁大學 === 資訊工程學系 === 98 === In the Web 2.0 Environment, user contents are aggregated through mashup. To ensure the security and privacy of the aggregated contents is an importance issue for service providers. With the OAuth support, content provider and content consumer could retrieve the content under owner’s approval. But OAuth does not deal with the following three relations at present: the relation between content owner and users; the relation between different content providers; and the relation between aggregated contents and the content users. The authorization server (AS) can be independent from the content provider services under OAuth 2.0. Content providers deploy the authorization rules on AS, and then AS could have more rooms for consideration in authorization decisions. AS could export authorization rules to other services. The consumer could make a decision while it shares the aggregated contents to other service according to the authorization rule that AS provided. In this thesis, we implement an AS prototype, and design the data structure of the authorization rule which is convenience for other services to deploy. This research analyze the relations about the content; associate the authorization rules from the content providers; identify the authorization conflict; notify the content owner, and make a decision when the contents are shared to other users. We made a mashup among Facebook, Google Health and Social Health Space, and implemented an AS prototype to verify the feasibility of the proposed mechanism.
author2 Mei Hsing
author_facet Mei Hsing
SAM CHI HOU
岑志豪
author SAM CHI HOU
岑志豪
spellingShingle SAM CHI HOU
岑志豪
An Extended Content Authorization Mechanism in Web Mashup
author_sort SAM CHI HOU
title An Extended Content Authorization Mechanism in Web Mashup
title_short An Extended Content Authorization Mechanism in Web Mashup
title_full An Extended Content Authorization Mechanism in Web Mashup
title_fullStr An Extended Content Authorization Mechanism in Web Mashup
title_full_unstemmed An Extended Content Authorization Mechanism in Web Mashup
title_sort extended content authorization mechanism in web mashup
publishDate 2010
url http://ndltd.ncl.edu.tw/handle/78965396786799721249
work_keys_str_mv AT samchihou anextendedcontentauthorizationmechanisminwebmashup
AT cénzhìháo anextendedcontentauthorizationmechanisminwebmashup
AT samchihou yīgèyúwǎngjìhùndāhuánjìngzhōngdekuòchōngnèiróngshòuquánjīzhì
AT cénzhìháo yīgèyúwǎngjìhùndāhuánjìngzhōngdekuòchōngnèiróngshòuquánjīzhì
AT samchihou extendedcontentauthorizationmechanisminwebmashup
AT cénzhìháo extendedcontentauthorizationmechanisminwebmashup
_version_ 1718233984549257216