Key-Based Cookie-Less Session Management Framework for Application Layer Security

Key-Based Cookie-Less Session Management Framework for Application Layer Security
复制标题

DOI:
10.1109/access.2019.2940331
复制
发表时间:
2019-09
期刊:
影响因子:
3.9
通讯作者:
Zahoor Ahmed Alizai;Hasan Tahir;Malik Hamza Murtaza;Shahzaib Tahir;K. Mcdonald-Maier
Zahoor Ahmed Alizai;Hasan Tahir;Malik Hamza Murtaza;Shahzaib Tahir;K. Mcdonald-Maier
中科院分区:
计算机科学3区
文献类型:
--
作者:
Zahoor Ahmed Alizai;Hasan Tahir;Malik Hamza Murtaza;Shahzaib Tahir;K. Mcdonald-Maier

文献摘要

被引文献

相似文献

本研究的目标是扩展安全套接字层(SSL)或传输层安全(TLS)等安全传输协议提供的保证,并将其应用于应用层。本文提出了一种允许多种安全机制统一的综合方案,从而从应用开发生命周期中消除了认证、相互认证、持续认证和会话管理的负担。拟议的方案将允许在扩展的安全规定的基础上建立高级别的安全机制,如访问控制和组身份验证。该方案有效地消除了对会话cookie、会话令牌和当前使用的任何类似技术的需要。从而减少了攻击面,消灭了一大批攻击载体。
The goal of this study is to extend the guarantees provided by the secure transmission protocols such as Secure Sockets Layer (SSL) or Transport Layer Security (TLS) and apply them to the application layer. This paper proposes a comprehensive scheme that allows the unification of multiple security mechanisms, thereby removing the burden of authentication, mutual authentication, continuous authentication, and session management from the application development life-cycle. The proposed scheme will allow creation of high-level security mechanisms such as access control and group authentication on top of the extended security provisions. This scheme effectively eliminates the need for session cookies, session tokens and any similar technique currently in use. Hence reducing the attack surface and nullifying a vast group of attack vectors.