Security Analysis of Web-based Identity Federation

نویسنده

  • Apurva Kumar
چکیده

While security of cross-domain single sign-on is a thoroughly researched subject, the closely related web identity federation has not been recognized as a distinct problem requiring analysis in its own right. In this paper, we describe a generic approach for analyzing security of web protocols through a framework for reasoning about user actions. We then use this framework to analyze security of important web identity federation protocols. We show that a secure single sign-on protocol does not necessarily ensure safety of linking identities across domains. Our analysis discovers limitations in current web identity management standards that can allow an attacker to create fraudulent identity associations across domains. We propose changes to the workflow and suggest measures for ensuring integrity of cross-domain associations in standard based implementations. Keywords-Security Protocols; Identity Management; Federated Identity; Web Security.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Browser-based identity federation

Given the increasing popularity of Web 2.0 applications, web-based three-party authentication gets more and more important. Identity federation fulfills this requirement through standardized protocols that authenticate Web users across trust domains. This thesis considers the problem of secure authentication by browser-based identity federation. This special class of identity federation only us...

متن کامل

Browser Model for Security Analysis of Browser-Based Protocols

Currently, many industrial initiatives focus on web-based applications. In this context an important requirement is that the user should only rely on a standard web browser. Hence the underlying security services also rely solely on a browser for interaction with the user. Browser-based identity federation is a prominent example of such a protocol. Unfortunately, very little is still known abou...

متن کامل

Cross-enterprise Identity Federation (OASIS - SAML) Implementation: An exploratory financial services case study

In the networked economy, strategic partnerships and collaboration are an important way to develop and maintain competitive advantages. At the same time, enterprises also need to reduce costs, increase revenues and seize new business opportunities. This demands enterprises to enable convenient and secure business interactions with internal and external stakeholders, and create relationships to ...

متن کامل

Dimensions of Identity Federation: A Case Study in Financial Services

In the networked economy, strategic partnerships and collaboration are an important way to develop and maintain competitive advantages. At the same time, enterprises also need to reduce costs, increase revenues and seize new business opportunities. This demands enterprises to enable convenient and secure business interactions with internal and external stakeholders, and create relationships to ...

متن کامل

Security for Web Services: Standards and Research Issues

This chapter identifies the main security requirements for Web services and it describes how such security requirements are addressed by standards for Web services security recently developed or under development by various standardizations bodies. Standards are reviewed according to a conceptual framework that groups them by the main functionalities they provide. Standards that are covered inc...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013