Android single sign-on security: Issues, taxonomy and directions
Android single sign-on security: Issues, taxonomy and directions
复制标题
Android 单点登录安全:问题、分类和方向
DOI:
10.1016/j.future.2018.06.049
复制
发表时间:
2018-12
影响因子:
7.5
通讯作者:
Zhu Sencun
中科院分区:
文献类型:
--
作者:
Liu Xing;Liu Jiqiang;Wang Wei;Zhu Sencun
Single Sign-On (SSO) is a mechanism that allows a user to log in to other applications using his identity registered with an identity provider. One of the most popular protocols for SSO is OAuth 2.0, which is an open standard for authorization. However, due to the lack of detailed instructions on how to implement OAuth 2.0 on Android, there are many vulnerabilities in the current Android OAuth 2.0 implementations. While much research effort has been made to exploit such vulnerabilities, there is a lack of systematical collation and summary of these researches, resulting in the appearance of common vulnerabilities in new applications. Hence, it is crucial to collate and summarize related work. Meanwhile, the rapid development of the Internet of Things (IoT) also requires an understanding of the usage of OAuth 2.0 in the IoT environment.In this work, we first describe the OAuth 2.0 authorization code grant flow and the implicit grant flow in detail and summarize the differences between the Web environment and the Android environment that affect OAuth 2.0 security. Then, we summarize the security issues in the implementations of OAuth 2.0 on Android. These security issues include: storing client_secret or access token locally, using embedded WebView as user-agent, incorrect usage of authentication proof, handling redirection in mobile app improperly, lacking transmission protection and third-party app authentication. Attacks on these vulnerabilities, such as WebView hijacking, linking hijacking and phishing, as well as attack results are elaborated subsequently. Against these security issues and attacks, we summarize the related research work in terms of vulnerability analysis, defense, and protocol analysis. At last, we discuss the directions for mitigating these security issues and discuss some OAuth-based protocols for the IoT environment.
登录
查看更多内容
DOI:
10.1145/2976749.2978385
发表时间:
2016-01
期刊:
Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
Daniel Fett;Ralf Küsters;G. Schmitz
通讯作者:
Daniel Fett;Ralf Küsters;G. Schmitz
DOI:
10.1109/asiajcis.2017.19
发表时间:
2017-08
期刊:
2017 12th Asia Joint Conference on Information Security (AsiaJCIS)
影响因子:
--
作者:
J. D. Ndibwile;Y. Kadobayashi;Doudou Fall
通讯作者:
J. D. Ndibwile;Y. Kadobayashi;Doudou Fall
DOI:
10.1109/sp.2015.62
发表时间:
2015-05
期刊:
2015 IEEE Symposium on Security and Privacy
影响因子:
--
作者:
Antonio Bianchi;Jacopo Corbetta;L. Invernizzi;Y. Fratantonio;Christopher Krügel;Giovanni Vigna
通讯作者:
Antonio Bianchi;Jacopo Corbetta;L. Invernizzi;Y. Fratantonio;Christopher Krügel;Giovanni Vigna
DOI:
--
发表时间:
2016
期刊:
--
影响因子:
--
作者:
Ronghai Yang;W. Lau;Tianyu Liu
通讯作者:
Ronghai Yang;W. Lau;Tianyu Liu
DOI:
10.1145/2818000.2818024
发表时间:
2015-12
期刊:
Proceedings of the 31st Annual Computer Security Applications Conference
影响因子:
--
作者:
Hui Wang;Yuanyuan Zhang;Juanru Li;Hui Liu;Wenbo Yang;Bodong Li;Dawu Gu
通讯作者:
Hui Wang;Yuanyuan Zhang;Juanru Li;Hui Liu;Wenbo Yang;Bodong Li;Dawu Gu