NOTE

How to Design Authentication and Authorization

Authentication, authorization, and credentials; common techniques; and how authentication and authorization are integrated into a microservice architecture.

Software Architecture & EngineeringCreated Updated 1 min readhistorical

This is a historical learning note and may contain outdated or incomplete understanding.

1. What Are Authentication and Authorization

  • Authentication: the identity of the current user, solving the question “Who am I?”
  • Authorization: what kinds of identities are allowed to access certain resources, solving the question “What can I do?”
  • Credential: the foundation of authentication and authorization, a medium that marks a visitor’s identity or rights.

2. Why Authentication and Authorization Are Needed

Security.

3. Authentication and Authorization Technologies

3.1. Authentication Technologies

3.1.1. HTTP Authentication

Base64.md

Disadvantage: Base64 can only be called encoding, not encryption.

Scenario: management backends such as routers.

3.1.2. HMAC (AK/SK) Authentication

The message authentication code in Security.md.

Disadvantage: the key must not be leaked.

Scenario: authentication between servers.

3.1.3. OpenID Connect

3.2. Authorization Technologies

3.2.1. OAuth

3.3. Credential Technologies

3.3.2. JWT

4. How a Microservice Architecture Integrates Authentication and Authorization

4.1. Authentication

How to Design User Registration and Login.md

Authentication and Authorization

4.2. Authorization

Use OAuth2.

4.3. Credentials

Cookie Session.

5. Authentication and Authorization Components

5.1. Spring Security OAuth2

6. References

Discussion

Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub