Аналіз використання ймовірнісних фільтрів для інвалідації токенів автентифікації у розподілених системах
Вантажиться...
Файли
Дата
Назва журналу
Номер ISSN
Назва тому
Анотація
The article investigates the problem of centralized user authentication in complex
distributed systems using cryptographic tokens based on JWT (JSON Web Token). Such systems
allow decreasing request processing times comparable with conventional centralized
authentication systems by allowing offline token verification. However, this creates problems
with revoking of compromised or blocked tokens. The traditional approach used in such
protocols as OAuth2, shifts this problem to the client side, complicating the client side and
making the API more difficult to use. The article discusses the use of an approach that allows
developers to keep all costs on the validation token validation on the server side without making
significant changes to the system by blocklists. It is suggested to use probabilistic filters to
transmit updates about blocked tokens. Such filters at the cost of losing some precision in
checking if the entry belongs to the set of elements, using significantly less memory than would
be necessary to store all the elements of the set. They are usually used to avoid slow operations
such as disk or network access. As a result, it significantly reduces the memory usage on the
services end and decreases the traffic volumes between the system components. The criteria for
evaluating the performance of probabilistic filters were discussed for the task of periodically
updating the lists of blocked identifiers of access tokens. Also various implementations of
probabilistic filters were analyzed according to criteria. At the end recommendations for the
application of specific probabilistic filters implementations and their parameters for distributed
systems of various sizes are provided
Опис
Ключові слова
УДК
Тип документа
Мова
Бібліографічний опис
Хрущак С. В., Ткаченко О. М., Бойко О. Р., Кошмелюк О. О. Аналіз використання ймовірнісних фільтрів для інвалідації токенів автентифікації у розподілених системах // Оптико-електронні інформаційно-енергетичні технології. 2024. Т. 47, № 1. С. 34-41.
Схвалення
Рецензія
Доповнено
Цитується в
Список використаної літератури (11)
- Hinrichs T.. Centralized vs. Distributed Authorization: the CAP theorem URL: https://www.styra.com/blog/centralized-vs-distributed-authorization-the-cap-theorem
- Neray G.. Best Practices for Authorization in Microservices. URL: https://www.osohq.com/post/microservices-authorization-patterns
- Eknert A.. 4 Best Practices for Microservices Authorization. URL: https://thenewstack.io/microservices/4-best-practices-for-microservices-authorization/
- RFC-7519: JSON Web token. URL: https://datatracker.ietf.org/doc/html/rfc7519
- RFC-6749: The OAuth 2.0 Authorization Framework. URL: https://www.rfc-editor.org/rfc/rfc6749
- KrakenD: Token Revocation. URL: https://www.krakend.io/docs/authorization/revoking-tokens/
- Peter C. Dillinger and Panagiotis Manolios. 2004. Bloom Filters in Probabilistic Verification. In Formal Methods in Computer-Aided Design, 5th International Conference, FMCAD 2004, Austin, Texas, USA, November 15-17, 2004, Proceedings (Lecture Notes in Computer Science), Alan J. Hu and Andrew K. Martin (Eds.), Vol. 3312. Springer, 367-381. https://doi.org/10.1007/978-3-540-30494-4_26
- Bonomi F., Mitzenmacher M., etc. An improved construction for counting bloom filters. In 14th Annual European Symposium on Algorithms, LNCS 4168, pages 684–695, 2006
- Paghand R., Rodler F.. Cuckoo hashing. Journal of Algorithms, 51(2): 122–144, May 2004
- Fan B., Andersen D. G., etc. Cuckoo Filter: Practically Better Than Bloom. Carnegie Mellon University, Intel Labs, Harvard University. URL:https://www.cs.cmu.edu/~binfan/papers/conext14_cuckoofilter.pdf