Efficient Cookie Revocation for Web Authentication

被引:0
|
作者
Ye, Ruopeng [1 ]
Chan, Agnes [1 ]
Zhu, Feng [1 ]
机构
[1] Northeastern Univ, Coll Comp & Informat Sci, Boston, MA 02115 USA
关键词
Cookie revocation; Web authentication;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Many web-based services use persistent cookies to store user authentication information on the disk. In these services, when a web browser connects to the server, it sends the persistent cookies to automate the authentication process so that the user does not need to type in the username or password. However, current web authentication architecture does not have a proper expiration mechanism. As a consequence, a hacker can use an expired cookie to gain unauthorized access to the web services. To fix this problem, we propose two schemes for the web servers to efficiently store and verify cookie state information. We show that these schemes can effectively stop the replay-attack from expired cookies and can be easily implemented.
引用
收藏
页码:320 / 329
页数:10
相关论文
共 50 条
  • [41] QuasiModo: Efficient certificate validation and revocation
    Elwailly, FF
    Gentry, C
    Ramzan, Z
    PUBLIC KEY CRYPTOGRAPHY - PKC 2004, PROCEEDINGS, 2004, 2947 : 375 - 388
  • [42] Efficient certificate revocation in vehicular communication
    Falk, Rainer
    Kohlmayer, Florian
    AUTOMOTIVE SECURITY, 2007, 2016 : 239 - 254
  • [43] An efficient revocation algorithm in group signatures
    Chen, ZW
    Wang, JL
    Wang, YM
    Huang, JW
    Huang, D
    INFORMATION SECURITY AND CRYPTOLOGY - ICISC 2003, 2004, 2971 : 339 - 351
  • [44] EPRV: Efficient Pseudonym Revocation in VANETs
    Chaib, Noureddine
    Lagraa, Nasreddine
    Yagoubi, Mohamed Bachir
    Bensaad, Mohamed Lahcen
    Lakas, Abderrahman
    AD HOC & SENSOR WIRELESS NETWORKS, 2017, 38 (1-4) : 199 - 225
  • [45] An efficient proxy signature scheme with revocation
    Das, ML
    Saxena, AT
    Gulati, VP
    INFORMATICA, 2004, 15 (04) : 455 - 464
  • [46] Efficient certificate revocation in vehicular communication
    Falk, Rainer
    Kohlmayer, Florian
    VDI Berichte, 2007, (2016): : 239 - 254
  • [47] Efficient group signature scheme with revocation
    Zhong H.
    Huang C.-L.
    Xu Y.
    Cui J.
    Tongxin Xuebao/Journal on Communications, 2016, 37 (10): : 18 - 24
  • [48] An efficient revocation scheme for stateless receivers
    Hwang, YH
    Kim, CH
    Lee, PJ
    PUBLIC KEY INFRASTRUCTURE, PROCEEDINGS, 2004, 3093 : 322 - 334
  • [49] Simple Authentication for the Web
    van der Horst, Timothy W.
    Seamons, Kent E.
    2007 THIRD INTERNATIONAL CONFERENCE ON SECURITY AND PRIVACY IN COMMUNICATION NETWORKS AND WORKSHOPS, 2007, : 473 - 482
  • [50] 用Cookie构建Web安全的实现
    马亚娜
    钱焕延
    孙亚民
    计算机工程, 2002, (11) : 34 - 35+75