NEBULA:适用于不透明旋转刷新令牌的与语言无关的规范
NEBULA: A Language - Independent Specification for Opaque Rotating Refresh Tokens
浏览论文内容
中文总结 AI 辅助
本文提出NEBULA规范及10种多语言参考实现,解决RFC 9700刷新令牌实现的安全差异问题,通过38个机器可读场景确保跨语言一致性,相关成果开源。
中文摘要 AI 辅助
刷新令牌是现代认证系统中最敏感的凭证之一:生命周期长、持有者类型,足以生成数天或数周的访问令牌。当前OAuth 2.0安全的最佳现行实践RFC 9700要求,向公共客户端颁发的刷新令牌必须在每次使用时进行旋转并附带重放(复用)检测,或受发送方约束。但该最佳现行实践规定的是策略,而非机制:它未规定有线格式、存储架构、验证步骤的顺序、并发约定,也未定义丢失响应重试或密钥旋转等边缘情况的语义。因此,实现可能在决定安全结果的关键边缘情况上存在差异。我们提出NEBULA,这是对RFC 9700刷新令牌模型的精确、与语言无关的规范,同时提供10种符合规范的参考实现(TypeScript、Python、Go、Rust、Java、PHP、C#、Ruby、Elixir、Dart)。NEBULA令牌是不透明的——一个128位的公共选择器和一个256位的秘密验证器,均为密码学安全伪随机数生成器输出,不携带任何声明和签名——因此令牌的有效性是服务器端状态的属性,而非密码学验证的结果。其一致性测试方法将行为套件以数据而非文本形式发布:一个机器可读文件中包含38个场景,每个实现通过一个针对各语言的轻量运行器执行这些场景,从而从结构上排除了因转录导致的偏差。我们描述该规范——包括一个比较并设置的旋转约定,可关闭并发刷新下复用检测的可复现旁路——分析其安全属性,包括后量子姿态,并报告跨语言一致性作为多实现安全规范的方法。该规范、实现和一致性制品均根据Apache许可证2.0开源。
英文摘要
Refresh tokens are among the most sensitive credentials in modern authentication systems: long-lived, bearer-style, and sufficient to mint access tokens for days or weeks. RFC 9700, the current Best Current Practice for OAuth 2.0 security, mandates that refresh tokens issued to public clients be rotated on every use with replay (reuse) detection, or be sender-constrained. But the BCP specifies policy, not mechanism: it prescribes no wire format, no storage schema, no ordering of verification steps, no concurrency contract, and no semantics for edge cases such as lost-response retries or key rotation. Implementations may therefore diverge in precisely the corner cases that determine security outcomes. We present NEBULA, a precise, language-independent specification of the RFC 9700 refresh-token model, together with ten conformant reference implementations (TypeScript, Python, Go, Rust, Java, PHP, C#, Ruby, Elixir, Dart). NEBULA tokens are opaque -- a 128-bit public selector and a 256-bit secret verifier, both CSPRNG output, carrying no claims and no signature -- so token validity is a property of server-side state rather than of cryptographic verification. Its conformance methodology publishes the behavioural suite as data rather than as prose: 38 scenarios in one machine-readable file that every implementation executes through a thin per-language runner, so that drift by transcription is structurally excluded. We describe the specification -- including a compare-and-set rotation contract that closes a reproducible bypass of reuse detection under concurrent refresh -- analyse its security properties including its post-quantum posture, and report on cross-language conformance as a method for multi-implementation security specifications. The specification, implementations, and conformance artefacts are open source under the Apache License 2.0.