æãèªã¿OpenID Authentication 2.0 - Draft11 (3) Protocol Overview
ã½ã¼ã¹ã¯Implementor's Draft: OpenID Authentication 2.0 - Draft 11ã§ãã
Protocol Overview
- ã¨ã³ãã¦ã¼ã¶ã¼ã¯User-Supplied Identifierãèªåãã¡ã®User-Agentçµç±ã§RPã«è¡¨ç¾ããäºããèªè¨¼ãéå§ãã¾ãã*1
- User-Supplied Identifierãæ¨æºåããå¾ã«ããã®*2ä¸ã§æ¢ç´¢ãå®è¡ããã¨ã³ãã¦ã¼ã¶ã¼ãèªè¨¼ã®çºã«ä½¿ãOP Endpoint URLã確ç«ãã¾ããUser-Supplied Identifierã¯ã»ã¯ã·ã§ã³7.3.1ã§è«è°ããã¦ããããã«ãOPã«ããã¦Claimed Identifierã®é¸æã許å¯ãã¦ããOP Identifierããããã¯Claimed Identifierã使ãäºç¡ãå®è¡ãããããã³ã«ã®çºã«æ¡å¼µçµç±ã§ãªãããä½ãä»ã®ãã便å©ãªç©ãããããªãã*3
- (ãªãã·ã§ã³)Relying Party(ã¢ããªã±ã¼ã·ã§ã³ã®äºã)ã¨OPã¯Diffel-Hellmanå ±ééµäº¤æã使ã£ã¦ä¿¡é ¼é¢ä¿ãå ±ééµã«ãã£ã¦æ§ç¯ãããOPã¯ãã®ä¿¡é ¼é¢ä¿(ã®ç¢ºç«ã)次ã®ã¡ãã»ã¼ã¸ã®åå³ã¨ããRPã¯ãã®ã¡ãã»ã¼ã¸ã確èªããã®ã«(ä¿¡é ¼é¢ä¿ã®ç¢ºç«ã)å©ç¨ããããã®äºã¯äºãã®èªè¨¼ãªã¯ã¨ã¹ããã¬ã¹ãã³ã¹ã®å¾ã«å¼ãç¶ã次ã®ç´æ¥çãªç½²å確èªã®çºã®ãªã¯ã¨ã¹ãã®å¿ è¦æ§ãåãé¤ãã*4
- RPã¯ã¨ã³ãã¦ã¼ã¶ã¼ã®User-AgentãOpenIDèªè¨¼ãªã¯ã¨ã¹ãã¨å ±ã«OPã«ãªãã¤ã¬ã¯ããããã
- OPã¯ã¨ã³ãã¦ã¼ã¶ã¼ãOpenID Authenticationãå®è¡ããäºã«ããèªè¨¼ãããããããããäºãæããã®ãããããç¨æããã*5
- ã¨ã³ãã¦ã¼ã¶ã¼ãèªåãã¡ã®OPã§èªè¨¼ããéã¨ããã®ãããªèªè¨¼ã®å¨å²ã«ãããããªãæµåã®ä¸ã§ã®ä½æ³ã«é¢ãã¦ã¯ãã®ææ¸ã®ç¯å²å¤ã§ããã
- OPã¯ã¨ã³ãã¦ã¼ã¶ã¼ã®User-Agentãèªè¨¼ã許å¯ãããã¨è¨ã主張ãããã¯èªè¨¼ã失æããã¨è¨ãã¡ãã»ã¼ã¸ã¨å ±ã«RPã«ãªãã¤ã¬ã¯ããããã
- RPã¯OPããåä¿¡ããReturn URLã®ç¢ºèªãå¾ãæ å ±ã®ç¢ºèªãç®ä¸ã®ç¢ºèªãä¿¡é ¼é¢ä¿ãããéã«ç¢ºç«ãããå ±ééµã使ç¨ããããç´æ¥çãªãªã¯ã¨ã¹ããOPã«éä¿¡ããäºã«ãã£ã¦ç½²å確èªãè¡ãã¨è¨ã£ããããªæ å ±ã確èªããã
ã¾ã¨ã
ãªãã§ä»æ§ã£ã¦ãããªããããããã ããw
ãã£ããè¨ãã°ã
- ãã©ã¦ã¶çµç±ã§èªåã®IDããµã¼ãã¹ã«ä¼ããã(ãµã¼ãã¹å´ã«ãããã©ã¼ã ã¨ãå¤å使ã£ã¦)
- ãµã¼ãã¹å´ã¯ãã®IDããèªè¨¼å±ã®ã¨ã³ããã¤ã³ãURLãè¦ã¤ããã
- ãªãã·ã§ã³ã§DHéµäº¤æã使ã£ã¦OPã¨ãµã¼ãã¹éã§å ±ééµãæã£ã¦ãè¯ãã(å¾ã§ä½è¨ãªOPã¨ãµã¼ãã¹éã®ç¢ºèªãç¡ããªã)
- ãµã¼ãã¹ã¯èªè¨¼è¦æ±ã¨å ±ã«ãã©ã¦ã¶ãã¨OPã«é£ã°ãã
- èªè¨¼ãå®è¡ããããããã¯èªè¨¼ãã©ã¼ã ãåºãã
- OPã¯èªè¨¼çµæã¨å ±ã«ã¦ã¼ã¶ã¼ããµã¼ãã¹ã«ãªãã¤ã¬ã¯ããããã
- ãµã¼ãã¹å´ã¯OPããåãåã£ããã¼ã¿ã®æ¤è¨¼ããã
ã£ã¦æãã§ãããã
*1:ã¤ã¾ãã¨ããã¨ã³ãã¦ã¼ã¶ã¼ã¯èªåãã¡ã®IDããã©ã¦ã¶çµç±ã§ã¢ããªã±ã¼ã·ã§ã³ã«ä¼ãããã£ã¦äº
*2:User-Supplied Identifierã®äº
*3:ããããããæå³ããããããã
*4:éµäº¤æãã¦ãã°ãããªãã¦è¯ãï¼
*5:ãããªãèªè¨¼ãããã®ãããããã¯èªããã¢ã«ã¦ã³ãæ å ±ãå ¥åãã¦èªè¨¼ããããã«èªè¨¼ãã©ã¼ã ãç¨æãããã£ã¦äºããªï¼