首页> 外文会议>Highlights of the Information Security Solutions Europe conference >Addressing Threats to Real-World Identity Management Systems
【24h】

Addressing Threats to Real-World Identity Management Systems

机译:解决真实界面管理系统的威胁

获取原文

摘要

Recent practical studies have revealed that, in practice, widely used identity management schemes such as OAuth 2.0 and OpenID Connect are often poorly implemented by relying parties, and as a result very serious vulnerabilities can result. In any event, any system relying on browser redirections, as is the case for OAuth 2.0 and OpenID Connect, is vulnerable to web-spoofing and phishing attacks. Many of these vulnerabilities would disappear if the user's browser (or other agent under user control) remained in charge of what credentials are divulged to whom, and when. We outline a system known as Uni-IdM, which has been successfully prototyped, which provides a generic service of this type. Through the installation of a simple JavaScript plugin, the user is provided with a unified means of managing and using all his or her credentials via a simple and intuitive interface, which will work with a multiplicity of identity management systems. This not only reduces the risk of credential and/or account compromise, but also greatly simplifies the work of the user in credential management as well as providing a much clearer view to the user of which end parties are being sent user information.
机译:最近的实践研究表明,在实践中,广泛使用的身份管理方案,如OAuth 2.0和OpenID Connect,通常通过依赖方来实现很差,因此可能导致非常严重的漏洞。在任何情况下,依赖于浏览器重定向的任何系统都是OAuth 2.0和OpenID Connect的情况,易受网络欺骗和网络钓鱼攻击。如果用户的浏览器(或用户控件下的其他代理)仍然负责凭证伪装的凭证,以及何时,其中许多漏洞将消失。我们概述了一个称为UNI-IDM的系统,该系统已成功原型,它提供了此类的通用服务。通过安装简单的JavaScript插件,用户提供了通过简单而直观的界面管理和使用他或她的凭据的统一手段,这将使用多种身份管理系统。这不仅降低了凭证和/或帐户妥协的风险,而且还大大简化了用户在凭证管理中的工作,以及向用户提供更清晰的用户提供更清晰的视图。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号