None
EN
Dual-Device Authorization with QR Codes
[]
Cendyne's Posts about security, architecture, software, management, and cryptography
That context, for authorization, has two components: a link to consent and verify intent to authorize this device, and a token that uniquely identifies this device's intent to receive authorization. The requesting device should show the QR code until it expires, at which point another should be generated or requested with an entirely different unique token that identifies this device to the consent service. A QR code is bound to the session on the requesting device, which links to an authorization service with a token identifying the requesting device.