GI LogoGI Logo
  • Anmelden
Digitale Bibliothek
    • Gesamter Bestand

      • Bereiche & Sammlungen
      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
    • Diese Sammlung

      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
Digital Bibliothek der Gesellschaft für Informatik e.V.
GI-DL
    • English
    • Deutsch
  • Deutsch 
    • English
    • Deutsch
Dokumentanzeige 
  •   Startseite
  • Fachbereiche
  • Informatik in den Lebenswissenschaften (ILW)
  • it - Information Technology
  • it - Information Technology 64(1-2) - April 2022
  • Dokumentanzeige
JavaScript is disabled for your browser. Some features of this site may not work without it.
  •   Startseite
  • Fachbereiche
  • Informatik in den Lebenswissenschaften (ILW)
  • it - Information Technology
  • it - Information Technology 64(1-2) - April 2022
  • Dokumentanzeige

Privacy-preserving Web single sign-on: Formal security analysis and design

Autor(en):
Schmitz, Guido [DBLP]
Zusammenfassung
Single sign-on (SSO) systems, such as OpenID and OAuth, allow Web sites to delegate user authentication to third parties, such as Facebook or Google. These systems provide a convenient mechanism for users to log in and ease the burden of user authentication for Web sites. Conversely, by integrating such SSO systems, they become a crucial part of the security of the modern Web. So far, it has been hard to prove if Web standards and protocols actually meet their security goals. SSO systems, in particular, need to satisfy strong security and privacy properties. In this thesis, we develop a new systematic approach to rigorously and formally analyze and verify such strong properties with the Web Infrastructure Model (WIM), the most comprehensive model of the Web infrastructure to date. Our analyses reveal severe vulnerabilities in SSO systems that lead to critical attacks against their security and privacy. We propose fixes and formally verify that our proposals are sufficient to establish security. Our analyses, however, also show that even Mozilla’s proposal for a privacy-preserving SSO system does not meet its unique privacy goal. To fill this gap, we use our novel approach to develop a new SSO system, SPRESSO, and formally prove that our system indeed enjoys strong security and privacy properties.
  • Vollständige Referenz
  • BibTeX
Schmitz, G., (2022). Privacy-preserving Web single sign-on: Formal security analysis and design.   it - Information Technology: Vol. 64, No. 1-2. Berlin: De Gruyter. (S. 43-48). DOI: 10.1515/itit-2022-0003
@article{mci/Schmitz2022,
author = {Schmitz, Guido},
title = {Privacy-preserving Web single sign-on: Formal security analysis and design},
journal = {it - Information Technology},
volume = {64},
number = {1-2},
year = {2022},
,
pages = { 43-48 } ,
doi = { 10.1515/itit-2022-0003 }
}

Sollte hier kein Volltext (PDF) verlinkt sein, dann kann es sein, dass dieser aus verschiedenen Gruenden (z.B. Lizenzen oder Copyright) nur in einer anderen Digital Library verfuegbar ist. Versuchen Sie in diesem Fall einen Zugriff ueber die verlinkte DOI: 10.1515/itit-2022-0003

Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken

Mehr Information

DOI: 10.1515/itit-2022-0003
ISSN: 2196-7032
Datum: 2022
Sprache: en (en)
Typ: Text/Journal Article

Keywords

  • formal analysis
  • single sign-on
  • authentication
  • privacy
  • web security
Sammlungen
  • it - Information Technology 64(1-2) - April 2022 [10]

Zur Langanzeige


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.

 

 


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.