Security analysis of the SAML Single Sign-on Browser Artifact profile

被引:25
|
作者
Gross, T [1 ]
机构
[1] IBM Corp, Zurich Res Lab, Zurich, Switzerland
关键词
D O I
10.1109/CSAC.2003.1254334
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Many influential industrial players are currently pursuing the development of new protocols for federated identity management. The Security Assertion Markup Language (SAML) is an important standardized example of this new protocol class and will be widely used in business-to-business scenarios to reduce user-management costs. SAML utilizes a constraint-based specification that is a popular design technique of this protocol class. It does not include a general security, analysis, but provides an attack-by-attack list of countermeasures as security, consideration. We present a security analysis of the SAML Single Sign-on Browser/Artifact profile, which is the first one for such a protocol standard. Our analysis of the protocol design reveals several flaws in the specification that can lead to vulnerable implementations. To demonstrate their impact, we exploit some of these flaws to mount attacks on the protocol.
引用
下载
收藏
页码:298 / 307
页数:10
相关论文
共 50 条
  • [31] Security of Mobile Single Sign-On: A Rational Reconstruction of Facebook Login Solution
    Sciarretta, Giada
    Armando, Alessandro
    Carbone, Roberto
    Ranise, Silvio
    SECRYPT: PROCEEDINGS OF THE 13TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS - VOL. 4, 2016, : 147 - 158
  • [32] Anatomy of the Facebook solution for mobile single sign-on: Security assessment and improvements
    Sciarretta, Giada
    Carbone, Roberto
    Ranise, Silvio
    Armando, Alessandro
    COMPUTERS & SECURITY, 2017, 71 : 71 - 86
  • [33] Design on a Single Sign-On Scheme
    Lei, Wen
    Liang, Xingjian
    Zhang, Hong
    ADVANCES IN SCIENCE AND ENGINEERING, PTS 1 AND 2, 2011, 40-41 : 531 - 536
  • [34] A taxonomy of single sign-on systems
    Pashalidis, A
    Mitchell, CJ
    INFORMATION SECURITY AND PRIVACY, PROCEEDINGS, 2003, 2727 : 249 - 264
  • [35] Single sign-on and the system administrator
    Grubb, MF
    Carter, R
    PROCEEDINGS OF THE TWELFTH SYSTEMS ADMINISTRATION CONFERENCE (LISA XII), 1998, : 63 - 86
  • [36] Scalable single sign-on system
    Huang, He
    Shan, Zhiguang
    Huang, Dongquan
    Journal of Southeast University (English Edition), 2007, 23 (03) : 465 - 468
  • [37] A Survey on Single Sign-On Techniques
    Radha, V.
    Reddy, D. Hitha
    2ND INTERNATIONAL CONFERENCE ON COMPUTER, COMMUNICATION, CONTROL AND INFORMATION TECHNOLOGY (C3IT-2012), 2012, 4 : 134 - 139
  • [38] Formal Analysis of A Single Sign-on Protocol Implementation for Android
    Ye, Quanqi
    Bai, Guangdong
    Wang, Kailong
    Dong, Jin Song
    2015 20TH INTERNATIONAL CONFERENCE ON ENGINEERING OF COMPLEX COMPUTER SYSTEMS (ICECCS), 2015, : 90 - 99
  • [39] Web services single sign-on protocol and formal analysis on it
    Zheng, DX
    Tang, SH
    Li, SF
    JOURNAL OF CIRCUITS SYSTEMS AND COMPUTERS, 2005, 14 (05) : 923 - 930
  • [40] Grid single sign-on in CCLRC
    Jensen, Jens
    Spence, David
    Viljoen, Matthew
    PROCEEDINGS OF THE UK E-SCIENCE ALL HANDS MEETING 2006, 2006, : 273 - +