首页> 外文OA文献 >The Web SSO Standard OpenID Connect: In-Depth Formal Security Analysis and Security Guidelines
【2h】

The Web SSO Standard OpenID Connect: In-Depth Formal Security Analysis and Security Guidelines

机译:Web ssO标准OpenID Connect:深入的正式安全分析   和安全指南

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Web-based single sign-on (SSO) services such as Google Sign-In and Log Inwith Paypal are based on the OpenID Connect protocol. This protocol enablesso-called relying parties to delegate user authentication to so-called identityproviders. OpenID Connect is one of the newest and most widely deployed singlesign-on protocols on the web. Despite its importance, it has not received muchattention from security researchers so far, and in particular, has notundergone any rigorous security analysis. In this paper, we carry out the first in-depth security analysis of OpenIDConnect. To this end, we use a comprehensive generic model of the web todevelop a detailed formal model of OpenID Connect. Based on this model, we thenprecisely formalize and prove central security properties for OpenID Connect,including authentication, authorization, and session integrity properties. In our modeling of OpenID Connect, we employ security measures in order toavoid attacks on OpenID Connect that have been discovered previously and newattack variants that we document for the first time in this paper. Based onthese security measures, we propose security guidelines for implementors ofOpenID Connect. Our formal analysis demonstrates that these guidelines are infact effective and sufficient.
机译:基于Web的单点登录(SSO)服务(例如Google登录和Paypal登录)基于OpenID Connect协议。该协议使所谓的依赖方能够将用户身份验证委托给所谓的身份提供者。 OpenID Connect是Web上最新,部署最广泛的单点登录协议之一。尽管它很重要,但到目前为止,它尚未受到安全研究人员的广泛关注,尤其是尚未进行任何严格的安全分析。在本文中,我们对OpenIDConnect进行了首次深入的安全性分析。为此,我们使用网络的综合通用模型来开发详细的OpenID Connect正式模型。然后,基于此模型,我们可以精确地形式化和证明OpenID Connect的中央安全属性,包括身份验证,授权和会话完整性属性。在我们对OpenID Connect的建模中,我们采用了安全措施,以避免以前发现的对OpenID Connect的攻击以及我们在本文中首次记录的新攻击变种。基于这些安全措施,我们为OpenID Connect的实施者提出了安全指南。我们的正式分析表明,这些指导原则实际上是有效且充分的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号