An Investigation of Identity-Account Inconsistency in Single Sign-On

An Investigation of Identity-Account Inconsistency in Single Sign-On
复制标题

DOI:
10.1145/3442381.3450085
复制
发表时间:
2021-04
期刊:
Proceedings of the Web Conference 2021
影响因子:
--
通讯作者:
Guannan Liu;Xing Gao;Haining Wang
Guannan Liu;Xing Gao;Haining Wang
中科院分区:
其他
文献类型:
--
作者:
Guannan Liu;Xing Gao;Haining Wang

文献摘要

相似文献

单点登录(SSO)由于其良好的可用性和安全性而被广泛用于在线认证。然而,它也引入了单点故障,因为所有服务提供商都完全信任由SSO身份提供商创建的用户的身份。在本文中,我们调查的身份帐户不一致的威胁,一个新的单点登录漏洞,可以导致在线帐户的妥协。存在该漏洞是因为当前SSO系统高度依赖用户的电子邮件地址来将帐户与真实的身份绑定,但忽略了电子邮件地址可能被其他用户重用的事实。我们发现,在SSO身份验证下,这种不一致性允许对手控制重复使用的电子邮件地址来接管相关的在线帐户,而不知道任何凭据,如密码。具体来说,我们首先对多个云电子邮件提供商的帐户管理政策进行了测量研究,显示了获取以前使用的电子邮件帐户的可行性。我们进一步对100个使用Google商业电子邮件服务和我们自己的域名的流行网站进行了系统研究,并证明大多数在线帐户都可以通过利用此不一致漏洞而受到损害。为了阐明电子邮件在野外的重用,我们分析了导致广泛存在的潜在电子邮件地址冲突的常用命名约定,并对美国大学的帐户政策进行了案例研究。最后,我们为最终用户、服务提供商和身份提供商提出了一些有用的做法,以防范这种身份-帐户不一致的威胁。
Single Sign-On (SSO) has been widely adopted for online authentication due to its favorable usability and security. However, it also introduces a single point of failure since all service providers fully trust the identity of a user created by the SSO identity provider. In this paper, we investigate the identity-account inconsistency threat, a new SSO vulnerability that can cause the compromise of online accounts. The vulnerability exists because current SSO systems highly rely on a user’s email address to bind an account with a real identity, but ignore the fact that email addresses might be reused by other users. We reveal that under the SSO authentication, such inconsistency allows an adversary controlling a reused email address to take over associated online accounts without knowing any credentials like passwords. Specifically, we first conduct a measurement study on the account management policies for multiple cloud email providers, showing the feasibility of acquiring previously used email accounts. We further perform a systematic study on 100 popular websites using the Google business email service with our own domain address and demonstrate that most online accounts can be compromised by exploiting this inconsistency vulnerability. To shed light on email reuse in the wild, we analyze the commonly used naming conventions that lead to a wide existence of potential email address collisions, and conduct a case study on the account policies of U.S. universities. Finally, we propose several useful practices for end-users, service providers, and identity providers to protect against this identity-account inconsistency threat.