Key-Based Cookie-Less Session Management Framework for Application Layer Security
Key-Based Cookie-Less Session Management Framework for Application Layer Security
复制标题
DOI:
10.1109/access.2019.2940331
复制
发表时间:
2019-09
期刊:
影响因子:
3.9
通讯作者:
Zahoor Ahmed Alizai;Hasan Tahir;Malik Hamza Murtaza;Shahzaib Tahir;K. Mcdonald-Maier
中科院分区:
文献类型:
--
作者:
Zahoor Ahmed Alizai;Hasan Tahir;Malik Hamza Murtaza;Shahzaib Tahir;K. Mcdonald-Maier
The goal of this study is to extend the guarantees provided by the secure transmission protocols such as Secure Sockets Layer (SSL) or Transport Layer Security (TLS) and apply them to the application layer. This paper proposes a comprehensive scheme that allows the unification of multiple security mechanisms, thereby removing the burden of authentication, mutual authentication, continuous authentication, and session management from the application development life-cycle. The proposed scheme will allow creation of high-level security mechanisms such as access control and group authentication on top of the extended security provisions. This scheme effectively eliminates the need for session cookies, session tokens and any similar technique currently in use. Hence reducing the attack surface and nullifying a vast group of attack vectors.