AI 中文总结
针对网络资源访问控制难题,提出基于SD-JWT标准的架构,直接在共享资源中嵌入加密签名与完整性保护,无需复杂IAM设施,简化部署并确保只读文件安全共享。
AI 中文摘要
对网络资源的访问控制一直是个长期挑战。传统解决方案依赖认证机制,带来身份与访问管理的额外复杂性,还存在安全风险。不同文件格式确保真实性和完整性的机制不同。本文提出基于选择性披露JSON网络令牌(SD-JWT)标准的架构来安全共享只读文件。该架构直接在共享资源中嵌入加密签名和完整性保护,无需复杂IAM基础设施,简化了部署并保障资源分发安全。
英文摘要
Access control to networked resources has been a longstanding challenge. The conventional solution relies on authentication mechanisms, which introduce additional complexities associated with Identity and Access Management (IAM). Such systems require user authentication, identity management, and authorization services, while also introducing security risks arising from vulnerabilities, misconfigurations, or implementation flaws. Furthermore, different file formats employ different mechanisms for ensuring authenticity and integrity through digital signatures. For example, PDF documents support the PDF Advanced Electronic Signature (PAdES) standard, whereas plain text files typically lack a standardized mechanism for embedding digital signatures. This paper proposes an architecture based on the Selective Disclosure JSON Web Token (SD-JWT) standard for securely sharing read-only files. The proposed architecture embeds cryptographic signatures and integrity protection directly into the shared resource, providing verifiable authenticity without relying on complex IAM infrastructures, such as centralized user databases, authentication services, or authorization mechanisms. By eliminating these components, the proposed solution simplifies deployment while maintaining strong security guarantees for the distribution of immutable resources.