Security Analysis of Web-based Identity Federation
نویسنده
چکیده
While security of cross-domain single sign-on is a thoroughly researched subject, the closely related web identity federation has not been recognized as a distinct problem requiring analysis in its own right. In this paper, we describe a generic approach for analyzing security of web protocols through a framework for reasoning about user actions. We then use this framework to analyze security of important web identity federation protocols. We show that a secure single sign-on protocol does not necessarily ensure safety of linking identities across domains. Our analysis discovers limitations in current web identity management standards that can allow an attacker to create fraudulent identity associations across domains. We propose changes to the workflow and suggest measures for ensuring integrity of cross-domain associations in standard based implementations. Keywords-Security Protocols; Identity Management; Federated Identity; Web Security.
منابع مشابه
Browser-based identity federation
Given the increasing popularity of Web 2.0 applications, web-based three-party authentication gets more and more important. Identity federation fulfills this requirement through standardized protocols that authenticate Web users across trust domains. This thesis considers the problem of secure authentication by browser-based identity federation. This special class of identity federation only us...
متن کاملBrowser Model for Security Analysis of Browser-Based Protocols
Currently, many industrial initiatives focus on web-based applications. In this context an important requirement is that the user should only rely on a standard web browser. Hence the underlying security services also rely solely on a browser for interaction with the user. Browser-based identity federation is a prominent example of such a protocol. Unfortunately, very little is still known abou...
متن کاملCross-enterprise Identity Federation (OASIS - SAML) Implementation: An exploratory financial services case study
In the networked economy, strategic partnerships and collaboration are an important way to develop and maintain competitive advantages. At the same time, enterprises also need to reduce costs, increase revenues and seize new business opportunities. This demands enterprises to enable convenient and secure business interactions with internal and external stakeholders, and create relationships to ...
متن کاملDimensions of Identity Federation: A Case Study in Financial Services
In the networked economy, strategic partnerships and collaboration are an important way to develop and maintain competitive advantages. At the same time, enterprises also need to reduce costs, increase revenues and seize new business opportunities. This demands enterprises to enable convenient and secure business interactions with internal and external stakeholders, and create relationships to ...
متن کاملSecurity for Web Services: Standards and Research Issues
This chapter identifies the main security requirements for Web services and it describes how such security requirements are addressed by standards for Web services security recently developed or under development by various standardizations bodies. Standards are reviewed according to a conceptual framework that groups them by the main functionalities they provide. Standards that are covered inc...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2013