{"id":1136,"date":"2018-08-21T09:00:59","date_gmt":"2018-08-21T16:00:59","guid":{"rendered":"https:\/\/www.microsoft.com\/zh-tw\/2018\/08\/21\/its-time-for-token-binding\/"},"modified":"2022-06-28T11:36:09","modified_gmt":"2022-06-28T18:36:09","slug":"its-time-for-token-binding","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/zh-tw\/microsoft-365\/blog\/2018\/08\/21\/its-time-for-token-binding\/","title":{"rendered":"\u7e6b\u7d50\u6b0a\u6756\u7684\u6642\u4ee3"},"content":{"rendered":"
\u5927\u5bb6\u597d\uff0c<\/p>\n
\u904e\u53bb\u5e7e\u500b\u6708\uff0c\u8eab\u5206\u8b58\u5225\u8207\u5b89\u5168\u6027\u6a19\u6e96\u9818\u57df\u7684\u767c\u5c55\u975e\u5e38\u4ee4\u4eba\u632f\u596e\u3002\u6211\u5011\u5728\u696d\u754c\u5404\u8def\u5c08\u5bb6\u7684\u52aa\u529b\u4e0b\u53d6\u5f97\u4e86\u9a5a\u4eba\u7684\u9032\u5c55\uff0c\u6700\u7d42\u78ba\u5b9a\u591a\u7a2e\u65b0\u6a19\u6e96\u8207\u6539\u826f\u6a19\u6e96\uff0c\u5c07\u540c\u6642\u6539\u5584\u96f2\u7aef\u670d\u52d9\u53ca\u88dd\u7f6e\u4e16\u4ee3\u7684\u5b89\u5168\u6027\u548c\u4f7f\u7528\u8005\u9ad4\u9a57\u3002<\/p>\n
\u9019\u4e9b\u6539\u9032\u4e2d\u6700\u91cd\u8981\u7684\u4e00\u74b0\u5373\u70ba\u6b0a\u6756\u7e6b\u7d50\u985e\u7684\u898f\u683c\uff0c\u76ee\u524d\u6b63\u5f85\u7db2\u969b\u7db2\u8def\u5de5\u7a0b\u4efb\u52d9\u63a8\u52d5\u5c0f\u7d44 (IETF)<\/a> \u7684\u6700\u7d42\u6838\u51c6 (\u5982\u679c\u60a8\u60f3\u8981\u6df1\u5165\u4e86\u89e3\u6b0a\u6756\u7e6b\u7d50\uff0c\u8acb\u89c0\u8cde Brian Campbell \u9019\u4efd\u7cbe\u5f69\u7c21\u5831<\/a>)\u3002<\/p>\n \u5728 Microsoft\uff0c\u6211\u5011\u76f8\u4fe1\u85c9\u7531\u8b93\u5168\u7403\u6bcf\u4e00\u4f4d\u958b\u767c\u4eba\u54e1\u90fd\u80fd\u5ee3\u6cdb\u3001\u8f15\u9b06\u5730\u4f7f\u7528\u9ad8\u5ea6\u8eab\u5206\u8b58\u5225\u8207\u9a57\u8b49\u4fdd\u8b49\uff0c\u6b0a\u6756\u7e6b\u7d50\u4fbf\u80fd\u540c\u6642\u5927\u5e45\u6539\u5584\u4f01\u696d\u8207\u5ba2\u6236\u74b0\u5883\u7684\u5b89\u5168\u6027\u3002<\/p>\n \u9452\u65bc\u975e\u5e38\u80af\u5b9a\u9019\u9805\u7cfb\u7d71\u7684\u6b63\u9762\u5f71\u97ff\uff0c\u6211\u5011\u5df2\u6301\u7e8c\u8207\u793e\u7fa4\u5408\u4f5c\uff0c\u81f4\u529b\u6253\u9020\u4e26\u63a1\u7528\u4e00\u7cfb\u5217\u7684\u6b0a\u6756\u7e6b\u7d50\u898f\u683c\u3002<\/p>\n \u5728\u9019\u4e9b\u898f\u683c\u5373\u5c07\u7372\u5f97\u8a8d\u53ef\u7684\u73fe\u5728\uff0c\u6211\u60f3\u8981\u547c\u7c72\u5404\u4f4d\u63a1\u53d6\u5169\u9805\u884c\u52d5\uff1a<\/p>\n \u540c\u6642\uff0c\u6211\u4e5f\u5f88\u69ae\u5e78\u5730\u5411\u60a8\u5831\u544a\uff0c\u696d\u754c\u6709\u591a\u80a1\u8072\u97f3<\/a>\u8a8d\u70ba\u6b0a\u6756\u7e6b\u7d50\u70ba\u4e00\u9805\u5373\u5c07\u5e36\u4f86\u91cd\u5927\u5f71\u97ff\u7684\u91cd\u8981\u89e3\u6c7a\u65b9\u6848\uff0c\u800c Microsoft \u4e5f\u662f\u5176\u4e2d\u4e4b\u4e00\u3002<\/p>\n \u63a5\u4e0b\u4f86\uff0c\u6211\u5c07\u4ea4\u7531\u696d\u754c\u9802\u5c16\u7684 Pamela Dingle \u4f86\u8aaa\u660e\u6b0a\u6756\u7e6b\u7d50\u4e4b\u6240\u4ee5\u8209\u8db3\u8f15\u91cd\u7684\u8a73\u7d30\u539f\u56e0\uff0c\u5979\u73fe\u5728\u4e5f\u65bc Microsoft \u64d4\u4efb Azure AD \u5718\u968a\u7684\u8eab\u5206\u8b58\u5225\u6a19\u6e96\u7e3d\u76e3\u3002<\/p>\n \u8b1d\u8b1d\u60a8\uff0c<\/p>\n Alex Simons (Twitter\uff1a@Alex_A_Simons<\/a>)<\/p>\n \u8a08\u5283\u7ba1\u7406\u7e3d\u76e3<\/p>\n Microsoft \u8eab\u5206\u8b58\u5225\u90e8\u9580<\/p>\n \u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2013<\/p>\n \u8b1d\u8b1d Alex\uff0c\u5927\u5bb6\u597d\uff0c<\/p>\n \u6211\u548c Alex \u4e00\u6a23\uff0c\u5c0d\u6211\u5011\u7684\u9032\u5c55\u611f\u5230\u975e\u5e38\u8208\u596e\uff01\u6211\u5011\u5df2\u6295\u5165\u6578\u5e74\u6642\u9593\u8207\u5fc3\u529b\u958b\u767c\u9019\u4e9b\u898f\u683c\uff0c\u5728\u63a5\u4e0b\u4f86\u5f88\u77ed\u7684\u6642\u9593\u5167\uff0c\u60a8\u5c31\u6703\u770b\u5230\u9019\u4e9b\u898f\u683c\u5c07\u88ab\u8996\u70ba\u65b0\u7684 RFC \u6a19\u6e96\u3002\u73fe\u5728\u6b63\u662f\u6642\u5019\u8b93\u67b6\u69cb\u898f\u5283\u5e2b\u6df1\u5165\u7814\u7a76\u6b0a\u6756\u7e6b\u7d50\uff0c\u4e86\u89e3\u5b83\u80fd\u5e36\u4f86\u7684\u7279\u5b9a\u8eab\u5206\u8b58\u5225\u8207\u5b89\u5168\u6027\u512a\u52e2\u3002<\/p>\n \u60a8\u53ef\u80fd\u6703\u554f\uff0c\u6b0a\u6756\u7e6b\u7d50\u7684\u512a\u9ede\u5230\u5e95\u5728\u54ea\uff1f\u6b0a\u6756\u7e6b\u7d50\u6280\u8853\u80fd\u91dd\u5c0d Cookies\u3001OAuth \u5b58\u53d6\u6b0a\u6756\u548c\u91cd\u65b0\u6574\u7406\u6b0a\u6756\uff0c\u4ee5\u53ca OpenID Connect \u7684\u8b58\u5225\u78bc\u6b0a\u6756\uff0c\u8b93\u5b83\u5011\u7121\u6cd5\u4f5c\u7528\u65bc\u6838\u767c\u7684\u7528\u6236\u6307\u5b9a TLS \u5167\u5bb9\u4e4b\u5916\u3002\u9019\u4e9b\u6b0a\u6756\u901a\u5e38\u90fd\u5c6c\u65bc\u300c\u6301\u6709\u4eba\u6b0a\u6756\u300d\uff0c\u610f\u601d\u662f\u6b0a\u6756\u7684\u6301\u6709\u8005\u53ef\u4ee5\u7528\u5b83\u5011\u4f86\u4ea4\u63db\u8cc7\u6e90\uff0c\u4f46\u6b0a\u6756\u7e6b\u7d50\u80fd\u9032\u4e00\u6b65\u6539\u5584\u9019\u7a2e\u6a21\u5f0f\uff0c\u65b9\u6cd5\u662f\u758a\u52a0\u4e00\u5c64\u78ba\u8a8d\u6a5f\u5236\uff0c\u91dd\u5c0d\u6b0a\u6756\u6838\u767c\u8207\u4f7f\u7528\u6642\u6536\u96c6\u5230\u7684\u5bc6\u78bc\u7de8\u8b6f\u6750\u6599\u9032\u884c\u6e2c\u8a66\u6bd4\u5c0d\u3002\u552f\u6709\u4f7f\u7528\u6b63\u78ba TLS \u983b\u9053\u7684\u6b63\u78ba\u7528\u6236\u624d\u80fd\u901a\u904e\u6e2c\u8a66\u3002\u9019\u9805\u5f37\u5236\u51fa\u793a\u6b0a\u6756\u4e4b\u5be6\u9ad4\u81ea\u8b49\u8cc7\u683c\u7684\u904e\u7a0b\u7a31\u70ba\u300c\u8b49\u660e\u6240\u6709\u6b0a\u300d\u3002<\/p>\n \u4e8b\u5be6\u8b49\u660e\uff0c\u6211\u5011\u80fd\u4ee5\u5404\u7a2e\u60e1\u610f\u624b\u6bb5\u5728\u539f\u59cb TLS \u5167\u5bb9\u5916\u4f7f\u7528 Cookies \u548c\u6b0a\u6756\uff0c\u4f8b\u5982\u52ab\u6301\u5f97\u4f86\u7684\u5de5\u4f5c\u968e\u6bb5 Cookies \u6216\u6d29\u6f0f\u7684\u5b58\u53d6\u6b0a\u6756\uff0c\u6216\u662f\u4f7f\u7528\u8907\u96dc\u7684 MiTM<\/a>\u3002\u9019\u5c31\u662f\u70ba\u4ec0\u9ebc IETF OAuth 2 Security Best Current Practice \u8349\u6848<\/a>\u6703\u5efa\u8b70\u63a1\u7528\u6b0a\u6756\u7e6b\u7d50\uff0c\u540c\u6642\u4e5f\u662f\u6211\u5011\u9078\u64c7\u5c07\u8eab\u5206\u8b58\u5225\u734e\u52f5\u8a08\u5283<\/a>\u734e\u9805\u52a0\u500d\u7684\u539f\u56e0\u3002\u5982\u679c\u653b\u64ca\u8005\u60f3\u8981\u4ee5\u975e\u539f\u59cb\u610f\u5716\u4ee5\u5916\u7684\u65b9\u5f0f\u96a8\u6a5f\u6216\u9810\u8b00\u4f7f\u7528 Cookies \u6216\u6b0a\u6756\uff0c\u6211\u5011\u4fbf\u80fd\u900f\u904e\u8981\u6c42\u8b49\u660e\u6240\u6709\u6b0a\uff0c\u5c07\u9019\u4e9b\u60c5\u6cc1\u8f49\u63db\u6210\u653b\u64ca\u8005\u96e3\u4ee5\u57f7\u884c\u6216\u662f\u7121\u6cd5\u8ca0\u64d4\u57f7\u884c\u4ee3\u50f9\u7684\u74b0\u5883\u3002<\/p>\n \u5c31\u50cf\u4efb\u4f55\u8b49\u660e\u6240\u6709\u6b0a\u6a5f\u5236\uff0c\u6b0a\u6756\u7e6b\u7d50\u80fd\u7d66\u4e88\u6211\u5011\u6253\u9020\u6df1\u5ea6\u9632\u79a6\u63aa\u65bd\u7684\u80fd\u529b\u3002\u6211\u5011\u53ef\u4ee5\u52aa\u529b\u9632\u6b62\u6b0a\u6756\u5916\u6d29\uff0c\u8207\u6b64\u540c\u6642\uff0c\u6211\u5011\u4e5f\u53ef\u4ee5\u9032\u884c\u9a57\u8b49\uff0c\u4ee5\u9632\u842c\u4e00\u3002\u8ddf\u7528\u6236\u7aef\u6191\u8b49\u9019\u985e\u8b49\u660e\u6240\u6709\u6b0a\u904e\u7a0b\u4e0d\u540c\u7684\u662f\uff0c\u6b0a\u6756\u7e6b\u7d50\u80fd\u5920\u7368\u7acb\u904b\u4f5c\u4e14\u7121\u9808\u4f7f\u7528\u8005\u4ecb\u5165\uff0c\u56e0\u70ba\u7d55\u5927\u591a\u6578\u5de5\u4f5c\u90fd\u6703\u7531\u57fa\u790e\u7d50\u69cb\u5b8c\u6210\u3002\u6211\u5011\u5e0c\u671b\u9019\u610f\u5473\u8457\u6700\u7d42\u6bcf\u500b\u4eba\u90fd\u80fd\u9078\u64c7\u662f\u5426\u9032\u884c\u9ad8\u968e\u8eab\u5206\u8b58\u5225\u4fdd\u8b49\uff0c\u4e0d\u904e\u9810\u8a08\u521d\u671f\u7684\u5f37\u52c1\u9700\u6c42\u5c07\u4f86\u81ea\u65bc\u653f\u5e9c\u548c\u91d1\u878d\u90e8\u9580\uff0c\u9452\u65bc\u6cd5\u898f\u6703\u8981\u6c42\u4ed6\u5011\u5373\u523b\u63a1\u7528\u8b49\u660e\u6240\u6709\u6b0a\u6a5f\u5236\u3002\u8209\u4f8b\u4f86\u8aaa\uff0c\u4efb\u4f55\u8981\u6c42 NIST 800-63C<\/a> AAL3 \u5206\u985e\u7684\u4eba\u90fd\u6703\u9700\u8981\u9019\u7a2e\u6280\u8853\u3002<\/p>\n \u6b0a\u6756\u7e6b\u7d50\u4ee3\u8868\u7684\u662f\u4e00\u689d\u6f2b\u9577\u7684\u65c5\u7a0b\u3002\u9019\u662f\u6211\u5011\u6295\u5165\u958b\u767c\u7684\u7b2c\u4e09\u5e74\uff0c\u96d6\u7136\u898f\u683c\u5373\u5c07\u53d7\u5230\u6838\u51c6\u662f\u9805\u4ee4\u4eba\u8208\u596e\u7684\u91cc\u7a0b\u7891\uff0c\u4e0d\u904e\u4ee5\u751f\u614b\u7cfb\u7d71\u800c\u8a00\u4ecd\u6709\u8a31\u591a\u9700\u8981\u5efa\u7f6e\u7684\u5de5\u4f5c\uff0c\u4e14\u9019\u9805\u898f\u683c\u9700\u8981\u52aa\u529b\u8de8\u8d8a\u4f9b\u61c9\u5546\u548c\u5e73\u53f0\u7684\u9694\u95a1\u624d\u7b97\u771f\u6b63\u6210\u529f\u3002\u6211\u5011\u5f88\u9ad8\u8208\u80fd\u5728\u672a\u4f86\u5e7e\u500b\u6708\u88e1\uff0c\u958b\u59cb\u8207\u60a8\u8a73\u7d30\u5206\u4eab\u63a1\u7528\u9019\u9805\u529f\u80fd\u5f8c\u6240\u7372\u5f97\u7684\u5b89\u5168\u512a\u52e2\u548c\u6700\u4f73\u505a\u6cd5\uff0c\u540c\u6642\u4e5f\u5e0c\u671b\u60a8\u80fd\u52a0\u5165\u6211\u5011\uff0c\u4e00\u8d77\u63d0\u5021\u9019\u9805\u6280\u8853\u3002<\/p>\n \u611f\u8b1d\u60a8\uff0c<\/p>\n \u2014 Pam<\/p>\n","protected":false},"excerpt":{"rendered":" \u5927\u5bb6\u597d\uff0c \u904e\u53bb\u5e7e\u500b\u6708\uff0c\u8eab\u5206\u8b58\u5225\u8207\u5b89\u5168\u6027\u6a19\u6e96\u9818\u57df\u7684\u767c\u5c55\u975e\u5e38\u4ee4\u4eba\u632f\u596e\u3002\u6211\u5011\u5728\u696d\u754c\u5404\u8def\u5c08\u5bb6\u7684\u52aa\u529b\u4e0b\u53d6\u5f97\u4e86\u9a5a\u4eba\u7684\u9032\u5c55\uff0c<\/p>\n","protected":false},"author":0,"featured_media":1137,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ep_exclude_from_search":false,"_classifai_error":"","footnotes":""},"content-type":[149],"product":[161,151],"audience":[196],"tags":[222],"coauthors":[],"class_list":["post-1136","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","content-type-news","product-enterprise-mobility-security","product-microsoft-365","audience-enterprise","tag-azure"],"yoast_head":"\n\n