On the security of Hölder-of-key single sign-on
Zusammenfassung
Web Single Sign-On (SSO) is a valuable point of attack because it provides
access to multiple resources once a user has initially authenticated. Therefore, the
security of Web SSO is crucial. In this context, the SAML-based Holder-of-Key (HoK)
SSO Profile is a cryptographically strong authentication protocol that is used in highly
critical scenarios. We show that HoK is susceptible to a previously published attack by
Armando et al. [ACC+11] that combines logical flaws with cross-site scripting. To fix
this vulnerability, we propose to enhance HoK and call our novel approach HoK+. We
have implemented HoK+ in the popular open source framework SimpleSAMLphp.
- Vollständige Referenz
- BibTeX
Mayer, A., Mladenov, V. & Schwenk, J.,
(2014).
On the security of Hölder-of-key single sign-on.
In:
Katzenbeisser, S., Lotz, V. & Weippl, E.
(Hrsg.),
Sicherheit 2014 – Sicherheit, Schutz und Zuverlässigkeit.
Bonn:
Gesellschaft für Informatik e.V..
(S. 65-78).
@inproceedings{mci/Mayer2014,
author = {Mayer, Andreas AND Mladenov, Vladislav AND Schwenk, Jörg},
title = {On the security of Hölder-of-key single sign-on},
booktitle = {Sicherheit 2014 – Sicherheit, Schutz und Zuverlässigkeit},
year = {2014},
editor = {Katzenbeisser, Stefan AND Lotz, Volkmar AND Weippl, Edgar} ,
pages = { 65-78 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
author = {Mayer, Andreas AND Mladenov, Vladislav AND Schwenk, Jörg},
title = {On the security of Hölder-of-key single sign-on},
booktitle = {Sicherheit 2014 – Sicherheit, Schutz und Zuverlässigkeit},
year = {2014},
editor = {Katzenbeisser, Stefan AND Lotz, Volkmar AND Weippl, Edgar} ,
pages = { 65-78 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken
Mehr Information
ISBN: 978-3-88579-622-0
ISSN: 1617-5468
Datum: 2014
Sprache:
(en)
(en)
Typ: Text/Conference Paper

