Logo des Repositoriums
 

Strengthening Web Authentication through TLS - Beyond TLS Client Certificates

dc.contributor.authorMayer, Andreas
dc.contributor.authorMladenov, Vladislav
dc.contributor.authorSchwenk, Jörg
dc.contributor.authorFeldmann, Florian
dc.contributor.authorMeyer, Christopher
dc.contributor.editorHühnlein, Detlef
dc.contributor.editorRoßnagel, Heiko
dc.date.accessioned2017-06-30T21:00:30Z
dc.date.available2017-06-30T21:00:30Z
dc.date.issued2014
dc.description.abstractEven though novel identification techniques like Single Sign-On (SSO) are on the rise, stealing the credentials used for the authentication is still possible. This situation can only be changed if we make novel use of the single cryptographic functionality a web browser offers, namely TLS. Although the use of client certificates for initial login has a long history, only two approaches to integrate TLS in the session cookie mechanism have been proposed so far: Origin Bound Client Certificates in [DCBW12], and the Strong Locked Same Origin Policy (SLSOP) in [KSTW07]. In this paper, we propose a third method based on the TLS-unique API proposed in RFC 5929 [AWZ10]: A single TLS session is uniquely identified through each of the two Finished messages exchanged during the TLS handshake, and RFC 5929 proposes to make the first Finished message available to higher layer protocols through a novel browser API. We show how this API can be used to strengthen all commonly used types of authentication, ranging from simple password based authentication and SSO to session cookie binding.en
dc.identifier.isbn978-3-88579-631-2
dc.identifier.pissn1617-5468
dc.language.isoen
dc.publisherGesellschaft für Informatik e.V.
dc.relation.ispartofOpen Identity Summit 2014
dc.relation.ispartofseriesLecture Notes in Informatics (LNI) - Proceedings, Volume P-237
dc.titleStrengthening Web Authentication through TLS - Beyond TLS Client Certificatesen
dc.typeText/Conference Paper
gi.citation.endPage108
gi.citation.publisherPlaceBonn
gi.citation.startPage97
gi.conference.date4.-6. November 2014
gi.conference.locationStuttgart

Dateien

Originalbündel
1 - 1 von 1
Vorschaubild nicht verfügbar
Name:
97.pdf
Größe:
608.65 KB
Format:
Adobe Portable Document Format