GI LogoGI Logo
  • Anmelden
Digitale Bibliothek
    • Gesamter Bestand

      • Bereiche & Sammlungen
      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
    • Diese Sammlung

      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
Digital Bibliothek der Gesellschaft für Informatik e.V.
GI-DL
    • English
    • Deutsch
  • Deutsch 
    • English
    • Deutsch
Dokumentanzeige 
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • Open Identity Summit
  • P237 - Open Identity Summit 2014
  • Dokumentanzeige
JavaScript is disabled for your browser. Some features of this site may not work without it.
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • Open Identity Summit
  • P237 - Open Identity Summit 2014
  • Dokumentanzeige

Strengthening Web Authentication through TLS - Beyond TLS Client Certificates

Autor(en):
Mayer, Andreas [DBLP] ;
Mladenov, Vladislav [DBLP] ;
Schwenk, Jörg [DBLP] ;
Feldmann, Florian [DBLP] ;
Meyer, Christopher [DBLP]
Zusammenfassung
Even though novel identification techniques like Single Sign-On (SSO) are on the rise, stealing the credentials used for the authentication is still possible. This situation can only be changed if we make novel use of the single cryptographic functionality a web browser offers, namely TLS. Although the use of client certificates for initial login has a long history, only two approaches to integrate TLS in the session cookie mechanism have been proposed so far: Origin Bound Client Certificates in [DCBW12], and the Strong Locked Same Origin Policy (SLSOP) in [KSTW07]. In this paper, we propose a third method based on the TLS-unique API proposed in RFC 5929 [AWZ10]: A single TLS session is uniquely identified through each of the two Finished messages exchanged during the TLS handshake, and RFC 5929 proposes to make the first Finished message available to higher layer protocols through a novel browser API. We show how this API can be used to strengthen all commonly used types of authentication, ranging from simple password based authentication and SSO to session cookie binding.
  • Vollständige Referenz
  • BibTeX
Mayer, A., Mladenov, V., Schwenk, J., Feldmann, F. & Meyer, C., (2014). Strengthening Web Authentication through TLS - Beyond TLS Client Certificates. In: Hühnlein, D. & Roßnagel, H. (Hrsg.), Open Identity Summit 2014. Bonn: Gesellschaft für Informatik e.V.. (S. 97-108).
@inproceedings{mci/Mayer2014,
author = {Mayer, Andreas AND Mladenov, Vladislav AND Schwenk, Jörg AND Feldmann, Florian AND Meyer, Christopher},
title = {Strengthening Web Authentication through TLS - Beyond TLS Client Certificates},
booktitle = {Open Identity Summit 2014},
year = {2014},
editor = {Hühnlein, Detlef AND Roßnagel, Heiko} ,
pages = { 97-108 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
DateienGroesseFormatAnzeige
97.pdf608.6Kb PDF Öffnen

Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken

Mehr Information

ISBN: 978-3-88579-631-2
ISSN: 1617-5468
Datum: 2014
Sprache: en (en)
Typ: Text/Conference Paper
Sammlungen
  • P237 - Open Identity Summit 2014 [15]

Zur Langanzeige


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.

 

 


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.