Cargando…

Authorizing Third-Party Applications Served through Messaging Platforms

The widespread adoption of smartphones and the new-generation wireless networks have changed the way that people interact among themselves and with their environment. The use of messaging platforms, such as WhatsApp, has become deeply ingrained in peoples’ lives, and many digital services have start...

Descripción completa

Detalles Bibliográficos
Autores principales: Sancho, Jorge, García, José, Alesanco, Álvaro
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2021
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8433987/
https://www.ncbi.nlm.nih.gov/pubmed/34502607
http://dx.doi.org/10.3390/s21175716
_version_ 1783751491763306496
author Sancho, Jorge
García, José
Alesanco, Álvaro
author_facet Sancho, Jorge
García, José
Alesanco, Álvaro
author_sort Sancho, Jorge
collection PubMed
description The widespread adoption of smartphones and the new-generation wireless networks have changed the way that people interact among themselves and with their environment. The use of messaging platforms, such as WhatsApp, has become deeply ingrained in peoples’ lives, and many digital services have started to be delivered using these communication channels. In this work, we propose a new OAuth grant type to be used when the interaction between the resource owner and the client takes place through a messaging platform. This new grant type firstly allows the authorization server to be sure that no Man-in-the-Middle risk exists between the resource owner and the client before issuing an access token. Secondly, it allows the authorization server to interact with the resource owner through the same user-agent already being used to interact with the client, i.e., the messaging platform, which is expected to improve the overall user experience of the authorization process. To verify this assumption, we conducted a usability study in which subjects were required to perform the full authorization process using both the standard authorization code grant type (through a web-browser) and the new grant type defined in this work. They have also been required to fill in a small questionnaire including some demographic information and their impressions about both authorization flows. The results suggest that the proposed grant type eases the authorization process in most cases.
format Online
Article
Text
id pubmed-8433987
institution National Center for Biotechnology Information
language English
publishDate 2021
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-84339872021-09-12 Authorizing Third-Party Applications Served through Messaging Platforms Sancho, Jorge García, José Alesanco, Álvaro Sensors (Basel) Article The widespread adoption of smartphones and the new-generation wireless networks have changed the way that people interact among themselves and with their environment. The use of messaging platforms, such as WhatsApp, has become deeply ingrained in peoples’ lives, and many digital services have started to be delivered using these communication channels. In this work, we propose a new OAuth grant type to be used when the interaction between the resource owner and the client takes place through a messaging platform. This new grant type firstly allows the authorization server to be sure that no Man-in-the-Middle risk exists between the resource owner and the client before issuing an access token. Secondly, it allows the authorization server to interact with the resource owner through the same user-agent already being used to interact with the client, i.e., the messaging platform, which is expected to improve the overall user experience of the authorization process. To verify this assumption, we conducted a usability study in which subjects were required to perform the full authorization process using both the standard authorization code grant type (through a web-browser) and the new grant type defined in this work. They have also been required to fill in a small questionnaire including some demographic information and their impressions about both authorization flows. The results suggest that the proposed grant type eases the authorization process in most cases. MDPI 2021-08-25 /pmc/articles/PMC8433987/ /pubmed/34502607 http://dx.doi.org/10.3390/s21175716 Text en © 2021 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Sancho, Jorge
García, José
Alesanco, Álvaro
Authorizing Third-Party Applications Served through Messaging Platforms
title Authorizing Third-Party Applications Served through Messaging Platforms
title_full Authorizing Third-Party Applications Served through Messaging Platforms
title_fullStr Authorizing Third-Party Applications Served through Messaging Platforms
title_full_unstemmed Authorizing Third-Party Applications Served through Messaging Platforms
title_short Authorizing Third-Party Applications Served through Messaging Platforms
title_sort authorizing third-party applications served through messaging platforms
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8433987/
https://www.ncbi.nlm.nih.gov/pubmed/34502607
http://dx.doi.org/10.3390/s21175716
work_keys_str_mv AT sanchojorge authorizingthirdpartyapplicationsservedthroughmessagingplatforms
AT garciajose authorizingthirdpartyapplicationsservedthroughmessagingplatforms
AT alesancoalvaro authorizingthirdpartyapplicationsservedthroughmessagingplatforms