首页> 外文期刊>Computers & Security >Anatomy of the Facebook solution for mobile single sign-on: Security assessment and improvements
【24h】

Anatomy of the Facebook solution for mobile single sign-on: Security assessment and improvements

机译:用于移动单点登录的Facebook解决方案剖析:安全评估和改进

获取原文
获取原文并翻译 | 示例

摘要

While there exist many secure authentication and authorization solutions for web applications, their adaptation in the mobile context is a new and open challenge. In this paper, we argue that the lack of a proper reference model for Single Sign-On (SSO) for mobile native applications drives many social network vendors (acting as Identity Providers) to develop their own mobile solution. However, as the implementation details are not well documented, it is difficult to establish the proper security level of these solutions. We thus provide a rational reconstruction of the Facebook SSO flow, including a comparison with the OAuth 2.0 standard and a security analysis obtained testing the Facebook SSO reconstruction against a set of identified SSO attacks. Based on this analysis, we have modified and generalized the Facebook solution proposing a native SSO abstract model and a related implementation capable of solving the identified vulnerabilities and accommodating any Identity Provider. Finally, we have analyzed the new native SSO solution proposed by the OAuth Working Group, extracted the related abstract model and made a comparison with our proposal.
机译:尽管存在许多针对Web应用程序的安全身份验证和授权解决方案,但它们在移动环境中的适应性是一个新的公开挑战。在本文中,我们认为缺少针对移动本机应用程序的单点登录(SSO)的适当参考模型会促使许多社交网络供应商(充当身份提供商)开发自己的移动解决方案。但是,由于没有详细记录实现细节,因此很难为这些解决方案建立适当的安全级别。因此,我们提供了Facebook SSO流程的合理重构,包括与OAuth 2.0标准的比较以及通过针对一组已识别的SSO攻击测试Facebook SSO重构而获得的安全性分析。基于此分析,我们对Facebook解决方案进行了修改和推广,提出了本机SSO抽象模型和相关解决方案,该解决方案能够解决已识别的漏洞并容纳任何身份提供者。最后,我们分析了OAuth工作组提出的新的本机SSO解决方案,提取了相关的抽象模型,并与我们的提议进行了比较。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号