Security analysis of the SAML Single Sign-on Browser Artifact profile

被引:25
|
作者
Gross, T [1 ]
机构
[1] IBM Corp, Zurich Res Lab, Zurich, Switzerland
关键词
D O I
10.1109/CSAC.2003.1254334
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Many influential industrial players are currently pursuing the development of new protocols for federated identity management. The Security Assertion Markup Language (SAML) is an important standardized example of this new protocol class and will be widely used in business-to-business scenarios to reduce user-management costs. SAML utilizes a constraint-based specification that is a popular design technique of this protocol class. It does not include a general security, analysis, but provides an attack-by-attack list of countermeasures as security, consideration. We present a security analysis of the SAML Single Sign-on Browser/Artifact profile, which is the first one for such a protocol standard. Our analysis of the protocol design reveals several flaws in the specification that can lead to vulnerable implementations. To demonstrate their impact, we exploit some of these flaws to mount attacks on the protocol.
引用
收藏
页码:298 / 307
页数:10
相关论文
共 50 条
  • [1] SAML & single sign-on
    Sivan, SS
    [J]. DR DOBBS JOURNAL, 2003, 28 (11): : 36 - +
  • [2] Security Vulnerabilities in SAML based Single Sign-On Authentication in Cloud
    Kaur, Kirandeep
    Bansal, Divya
    [J]. PROCEEDINGS OF THE 1ST INTERNATIONAL WORKSHOP ON CLOUD COMPUTING AND INFORMATION SECURITY (CCIS 2013), 2013, 52 : 294 - 298
  • [3] SAML-Based Single Sign-On for Legacy System
    Nie, Fengming
    Xu, Feng
    Qi, Rongzhi
    [J]. 2012 IEEE INTERNATIONAL CONFERENCE ON AUTOMATION AND LOGISTICS (ICAL), 2012, : 470 - 473
  • [4] Design and implementaion of a Single sign-on library supporting SAML (Security assertion markup language) for Grid and Web services security
    Shin, D
    Jeong, J
    Shin, D
    [J]. GRID AND COOPERATIVE COMPUTING, PT 2, 2004, 3033 : 557 - 564
  • [5] Security Analysis of a Single Sign-On Mechanism for Distributed Computer Networks
    Wang, Guilin
    Yu, Jiangshan
    Xie, Qi
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2013, 9 (01) : 294 - 302
  • [6] UniWare: A novel security Single Sign-On model
    Liu, Shuang
    Zhao, Zheng
    Xue, Guixiang
    Shi, Wei
    [J]. 2008 PROCEEDINGS OF INFORMATION TECHNOLOGY AND ENVIRONMENTAL SYSTEM SCIENCES: ITESS 2008, VOL 4, 2008, : 418 - 421
  • [7] A Model of Unite-Authentication Single Sign-On Based on SAML underlying Web
    Wu Kaixing
    Yu Xiaolin
    [J]. ICIC 2009: SECOND INTERNATIONAL CONFERENCE ON INFORMATION AND COMPUTING SCIENCE, VOL 2, PROCEEDINGS: IMAGE ANALYSIS, INFORMATION AND SIGNAL PROCESSING, 2009, : 211 - 213
  • [8] SAML Single Sign-On Protocol Development Using Combination of Speech and Speaker Recognition
    Telnoni, Patrick
    Munir, Rinaldi
    Rosmansyah, Yusep
    [J]. 2014 INTERNATIONAL CONFERENCE OF ADVANCED INFORMATICS: CONCEPT, THEORY AND APPLICATION (ICAICTA), 2014, : 299 - 304
  • [9] Single Sign-on Implementation: Leveraging Browser Storage for Handling Tabbed Browsing Sign-outs
    Ramamoorthi, Lokesh
    Sarkar, Dilip
    [J]. DEVELOPMENTS AND ADVANCES IN DEFENSE AND SECURITY, 2020, 152 : 15 - 28
  • [10] SECURITY AT SIGN-ON TIME
    RAMSGARD, WC
    [J]. JOURNAL OF SYSTEMS MANAGEMENT, 1982, 33 (02): : 32 - 33