douqian2957 2015-04-17 10:08
浏览 87
已采纳

为API身份验证添加UTC时间戳是一个好主意

I have seen many sites such as

Amazon : (http://docs.aws.amazon.com/AmazonS3/latest/dev/RESTAuthentication.html) adding UTC timestamp("seconds since epoch") to HMAC for stopping replay attacks.

Many authentication tutorials and forums like How to securely maintain user authentication through a third party API? are also suggesting this.

I have only one concern in this, can it cause issue when mobile apps communicate with the API, I have checked it will not cause issue on Web when communicating with API's on web with PHP.

  • 写回答

1条回答 默认 最新

  • douxi8119 2015-04-17 11:46
    关注

    The idea with Amazon S3 is:

    1. their API will create a link with the timestamp
    2. amazon stores this timestamp and request separately
    3. you will use that link
    4. amazon will check if it is not expired for given request

    For you as a user has that timestamp just a informative character and you can do whatever you want with it, it doesn't matter at all. Amazon compares stored timestamp with Amazons servertime...

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 训练的多模态特征融合模型准确度很低怎么办
  • ¥15 kylin启动报错log4j类冲突
  • ¥15 超声波模块测距控制点灯,灯的闪烁很不稳定,经过调试发现测的距离偏大
  • ¥15 import arcpy出现importing _arcgisscripting 找不到相关程序
  • ¥15 onvif+openssl,vs2022编译openssl64
  • ¥15 iOS 自定义输入法-第三方输入法
  • ¥15 很想要一个很好的答案或提示
  • ¥15 扫描项目中发现AndroidOS.Agent、Android/SmsThief.LI!tr
  • ¥15 怀疑手机被监控,请问怎么解决和防止
  • ¥15 Qt下使用tcp获取数据的详细操作