메뉴 건너뛰기




Volumn 31, Issue 4, 2012, Pages 465-483

Systematically breaking and fixing OpenID security: Formal analysis, semi-automated empirical evaluation, and practical countermeasures

Author keywords

Authentication; Empirical evaluation; OpenID; Security protocol analysis; Web application security; Web single sign on

Indexed keywords

EMPIRICAL EVALUATIONS; OPENID; SECURITY PROTOCOL ANALYSIS; SINGLE SIGN ON; WEB APPLICATION SECURITY;

EID: 84861098079     PISSN: 01674048     EISSN: None     Source Type: Journal    
DOI: 10.1016/j.cose.2012.02.005     Document Type: Article
Times cited : (38)

References (37)
  • 2
    • 78650115461 scopus 로고    scopus 로고
    • [Online; accessed 23.08.11]
    • AOL LLC AOL open authentication API January 2008 http://dev.aol.com/api/ openauth [Online; accessed 23.08.11]
    • (2008) AOL Open Authentication API
    • Llc, A.1
  • 5
    • 77950854725 scopus 로고    scopus 로고
    • [Online; accessed 23.08.11]
    • J. Bufu OpenID4Java 2009 http://code.google.com/p/openid4java/ [Online; accessed 23.08.11]
    • (2009) OpenID4Java
    • Bufu, J.1
  • 6
    • 23144446730 scopus 로고    scopus 로고
    • Deconstructing Alice and Bob
    • DOI 10.1016/j.entcs.2005.06.007, PII S1571066105050498, Proceedings of the Second Workshop on Automated Reasoning for Security Protocol Analysis (ARSPA 2005)
    • C. Caleiro, L. Vigan, and D. Basin Deconstructing Alice and Bob Electronic Notes in Theoretical Computer Science 135 1 2005 3 22 URL: http://www.sciencedirect.com/science/article/pii/S1571066105050498 (Pubitemid 41082142)
    • (2005) Electronic Notes in Theoretical Computer Science , vol.135 , pp. 3-22
    • Caleiro, C.1    Vigano, L.2    Basin, D.3
  • 10
  • 11
    • 35348884906 scopus 로고    scopus 로고
    • A large-scale study of web password habits
    • DOI 10.1145/1242572.1242661, 16th International World Wide Web Conference, WWW2007
    • D. Florencio, and C. Herley A large-scale study of web password habits Proceedings of the 16th International Conference on World Wide Web (WWW'07) 2007 ACM New York, NY, USA 657 666 (Pubitemid 47582295)
    • (2007) 16th International World Wide Web Conference, WWW2007 , pp. 657-666
    • Florencio, D.1    Herley, C.2
  • 12
    • 34250729756 scopus 로고    scopus 로고
    • Password management strategies for online accounts
    • DOI 10.1145/1143120.1143127, ACM International Conference Proceeding Series - Proceedings of the Second Symposium on Usable Privacy and Security, SOUPS 2006
    • S. Gaw, and E.W. Felten Password management strategies for online accounts Proceedings of the Second Symposium on Usable Privacy and Security (SOUPS'06) 2006 44 55 (Pubitemid 46966968)
    • (2006) ACM International Conference Proceeding Series , vol.149 , pp. 44-55
    • Gaw, S.1    Felten, E.W.2
  • 13
    • 57349145344 scopus 로고    scopus 로고
    • [Online; accessed 23.08.11]
    • R. Graham Sidejacking with hamster August 2007 http://erratasec.blogspot. com/2007/08/sidejacking-with-hamster-05.html [Online; accessed 23.08.11]
    • (2007) Sidejacking with Hamster
    • Graham, R.1
  • 16
    • 0031633395 scopus 로고    scopus 로고
    • Casper: A compiler for the analysis of security protocols
    • URL
    • G. Lowe Casper: a compiler for the analysis of security protocols Journal of Computer Security 6 1 1998 53 84 URL: http://iospress.metapress.com/content/ ADNXU4KPRPL21RC9
    • (1998) Journal of Computer Security , vol.6 , Issue.1 , pp. 53-84
    • Lowe, G.1
  • 18
    • 84861097923 scopus 로고    scopus 로고
    • Oasis [Online; accessed 23.12.11]
    • OASIS OASIS extensible resource identifier 2008 www.oasis-open.org/ committees/xri/ [Online; accessed 23.12.11]
    • (2008) OASIS Extensible Resource Identifier
  • 20
    • 1642359636 scopus 로고    scopus 로고
    • Microsoft.NET Passport and identity management
    • R. Oppliger Microsoft.NET Passport and identity management Information Security Technical Report 9 1 2004 26 34
    • (2004) Information Security Technical Report , vol.9 , Issue.1 , pp. 26-34
    • Oppliger, R.1
  • 21
    • 84861093336 scopus 로고    scopus 로고
    • Owasp [Online; accessed 23.08.11]
    • OWASP Session hijacking attack 2009 https://www.owasp.org/index.php/ Session-hijacking-attack [Online; accessed 23.08.11]
    • (2009) Session Hijacking Attack
  • 28
    • 38149086751 scopus 로고    scopus 로고
    • Drive-by pharming
    • Lecture notes in Computer Science Springer Berlin/Heidelberg
    • S. Stamm, Z. Ramzan, and M. Jakobsson Drive-by pharming Information and communications security Lecture notes in Computer Science vol. 4861 2007 Springer Berlin/Heidelberg 495 506
    • (2007) Information and Communications Security , vol.4861 , pp. 495-506
    • Stamm, S.1    Ramzan, Z.2    Jakobsson, M.3


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.