首页> 外文OA文献 >Security in Single Sign-On Web Applications: An Assessment of the Security in and Between Web Applications Sharing a Common Single Sign-On User Session
【2h】

Security in Single Sign-On Web Applications: An Assessment of the Security in and Between Web Applications Sharing a Common Single Sign-On User Session

机译:单一登录Web应用程序中的安全性:对共享公共单一登录用户会话的Web应用程序内部和之间的安全性进行评估

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Single Sign-On (SSO) is a solution where the authentication process is taken care of once by a third-party Web site rather than at each of the the Web sites providing services to their users. This new way of separating user identities from the service-providing Web sites leads to different security requirements. As an approach towards assessing the security of Web applications utilizing SSO, this thesis investigates the concepts and functionality of OpenID, a decentralized authentication protocol. The assessment addresses vulnerabilities and threats related to SSO, using real Web applications as examples. Development of an OpenID-enabled Web application is a part of the security assessment. The thesis includes experimenting with various OpenID-enabled Web sites and Identity Providers (IdPs), and observing how they are affected by different kinds of Web security threats. The results of the thesis shows how security weaknesses were discovered at two major IdPs by performing Clickjaking attacks. Also, the thesis outlines some attacks that are threatening the concept of SSO in general.
机译:单一登录(SSO)是一种解决方案,其中身份验证过程由第三方网站负责一次,而不是在为用户提供服务的每个网站上进行。这种将用户身份与提供服务的网站分开的新方法导致了不同的安全要求。作为一种利用SSO评估Web应用程序安全性的方法,本文研究了分散式身份验证协议OpenID的概念和功能。该评估以真实的Web应用程序为例,解决了与SSO相关的漏洞和威胁。支持OpenID的Web应用程序的开发是安全评估的一部分。本文包括对各种启用OpenID的网站和身份提供程序(IdP)进行试验,并观察它们如何受到各种Web安全威胁的影响。论文的结果表明如何通过执行Clickjaking攻击在两个主要的IdP上发现安全漏洞。此外,本文还概述了总体上威胁SSO概念的一些攻击。

著录项

  • 作者

    Grimstad Jo;

  • 作者单位
  • 年度 2010
  • 总页数
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号