Privacy-preserving Web single sign-on: Formal security analysis and design

被引:0
|
作者
Schmitz, Guido [1 ]
机构
[1] Royal Holloway Univ London, Informat Secur Grp, Egham, Surrey, England
来源
IT-INFORMATION TECHNOLOGY | 2022年 / 64卷 / 1-2期
关键词
formal analysis; single sign-on; authentication; privacy; web security;
D O I
10.1515/itit-2022-0003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Single sign-on (SSO) systems, such as OpenID and OAuth, allow Web sites to delegate user authentication to third parties, such as Facebook or Google. These systems provide a convenient mechanism for users to log in and ease the burden of user authentication for Web sites. Conversely, by integrating such SSO systems, they become a crucial part of the security of the modern Web. So far, it has been hard to prove if Web standards and protocols actually meet their security goals. SSO systems, in particular, need to satisfy strong security and privacy properties. In this thesis, we develop a new systematic approach to rigorously and formally analyze and verify such strong properties with the Web Infrastructure Model (WIM), the most comprehensive model of the Web infrastructure to date. Our analyses reveal severe vulnerabilities in SSO systems that lead to critical attacks against their security and privacy. We propose fixes and formally verify that our proposals are sufficient to establish security. Our analyses, however, also show that even Mozilla's proposal for a privacy-preserving SSO system does not meet its unique privacy goal. To fill this gap, we use our novel approach to develop a new SSO system, SPRESSO, and formally prove that our system indeed enjoys strong security and privacy properties.
引用
收藏
页码:43 / 48
页数:6
相关论文
共 50 条
  • [1] Decentralized, Privacy-Preserving, Single Sign-On
    Mir, Omid
    Roland, Michael
    Mayrhofer, Rene
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [2] PriSign, A Privacy-Preserving Single Sign-On System for Cloud Environments
    Shi, Rui
    Yang, Yang
    Xie, Huiqin
    Feng, Huamin
    Shi, Guozhen
    Zhang, Jianyi
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (02):
  • [3] Ticket Transparency: Accountable Single Sign-On with Privacy-Preserving Public Logs
    Chu, Dawei
    Lin, Jingqiang
    Li, Fengjun
    Zhang, Xiaokun
    Wang, Qiongxiao
    Liu, Guangqi
    [J]. SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM, PT I, 2019, 304 : 511 - 531
  • [4] Web services single sign-on protocol and formal analysis on it
    Zheng, DX
    Tang, SH
    Li, SF
    [J]. JOURNAL OF CIRCUITS SYSTEMS AND COMPUTERS, 2005, 14 (05) : 923 - 930
  • [5] MISO: Legacy-compatible Privacy-preserving Single Sign-on using Trusted Execution Environments
    Xu, Rongwu
    Yang, Sen
    Zhang, Fan
    Fang, Zhixuan
    [J]. 2023 IEEE 8TH EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY, EUROS&P, 2023, : 352 - 372
  • [6] Design of a scalable single sign-on for web service
    Huang, He
    Liu, Qingwen
    Zhao, Liang
    Liu, Fengchen
    [J]. 2007 INTERNATIONAL SYMPOSIUM ON COMPUTER SCIENCE & TECHNOLOGY, PROCEEDINGS, 2007, : 384 - 388
  • [7] Formal Analysis of A Single Sign-on Protocol Implementation for Android
    Ye, Quanqi
    Bai, Guangdong
    Wang, Kailong
    Dong, Jin Song
    [J]. 2015 20TH INTERNATIONAL CONFERENCE ON ENGINEERING OF COMPLEX COMPUTER SYSTEMS (ICECCS), 2015, : 90 - 99
  • [8] SPRESSO: A Secure, Privacy-Respecting Single Sign-On System for the Web
    Fett, Daniel
    Kuesters, Ralf
    Schmitz, Guido
    [J]. CCS'15: PROCEEDINGS OF THE 22ND ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2015, : 1358 - 1369
  • [9] Formal security definition and efficient construction for roaming with a privacy-preserving extension
    Yang, Guomin
    Wong, Duncan S.
    Deng, Xiaotie
    [J]. JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2008, 14 (03) : 441 - 462
  • [10] Design of single sign-on
    Zhao, G
    Zheng, D
    Chen, KF
    [J]. PROCEEDINGS OF THE IEEE INTERNATIONAL CONFERENCE ON E-COMMERCE TECHNOLOGY FOR DYNAMIC E-BUSINESS, 2004, : 253 - 256