Android single sign-on security: Issues, taxonomy and directions

Android single sign-on security: Issues, taxonomy and directions
复制标题

Android 单点登录安全:问题、分类和方向

DOI:
10.1016/j.future.2018.06.049
复制
发表时间:
2018-12
影响因子:
7.5
通讯作者:
Zhu Sencun
Zhu Sencun
中科院分区:
计算机科学2区
文献类型:
--
作者:
Liu Xing;Liu Jiqiang;Wang Wei;Zhu Sencun

文献摘要

参考文献

相似文献

单点登录(SSO)是一种允许用户使用其在身份提供者处注册的身份登录到其他应用程序的机制。最流行的SSO协议之一是OAuth 2.0,这是一个开放的授权标准。然而,由于缺乏关于如何在Android上实现OAuth 2.0的详细说明,目前Android OAuth 2.0实现中存在许多漏洞。虽然针对这类漏洞进行了大量的研究工作,但缺乏系统的整理和总结,导致新应用中出现了常见的漏洞。因此,整理和总结相关工作至关重要。同时,物联网(IoT)的快速发展也要求了解OAuth 2.0在物联网环境中的使用情况,本文首先详细描述了OAuth 2.0授权码授权流程和隐式授权流程,总结了Web环境和Android环境下影响OAuth 2.0安全性的差异。然后,我们总结了OAuth 2.0在Android上实现的安全问题。这些安全问题包括:本地存储client_secret或访问令牌、使用嵌入式WebView作为用户代理、身份验证证明使用不正确、移动的应用程序中的重定向处理不正确、缺乏传输保护和第三方应用程序身份验证。随后详细介绍了针对这些漏洞的WebView劫持、链接劫持、网络钓鱼等攻击方法以及攻击结果。针对这些安全问题和攻击,从漏洞分析、防御、协议分析等方面总结了相关的研究工作。最后,我们讨论了缓解这些安全问题的方向,并讨论了物联网环境中一些基于OAuths的协议。
Single Sign-On (SSO) is a mechanism that allows a user to log in to other applications using his identity registered with an identity provider. One of the most popular protocols for SSO is OAuth 2.0, which is an open standard for authorization. However, due to the lack of detailed instructions on how to implement OAuth 2.0 on Android, there are many vulnerabilities in the current Android OAuth 2.0 implementations. While much research effort has been made to exploit such vulnerabilities, there is a lack of systematical collation and summary of these researches, resulting in the appearance of common vulnerabilities in new applications. Hence, it is crucial to collate and summarize related work. Meanwhile, the rapid development of the Internet of Things (IoT) also requires an understanding of the usage of OAuth 2.0 in the IoT environment.In this work, we first describe the OAuth 2.0 authorization code grant flow and the implicit grant flow in detail and summarize the differences between the Web environment and the Android environment that affect OAuth 2.0 security. Then, we summarize the security issues in the implementations of OAuth 2.0 on Android. These security issues include: storing client_secret or access token locally, using embedded WebView as user-agent, incorrect usage of authentication proof, handling redirection in mobile app improperly, lacking transmission protection and third-party app authentication. Attacks on these vulnerabilities, such as WebView hijacking, linking hijacking and phishing, as well as attack results are elaborated subsequently. Against these security issues and attacks, we summarize the related research work in terms of vulnerability analysis, defense, and protocol analysis. At last, we discuss the directions for mitigating these security issues and discuss some OAuth-based protocols for the IoT environment.
DOI: 10.1145/2976749.2978385
发表时间: 2016-01
期刊: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Daniel Fett;Ralf Küsters;G. Schmitz
通讯作者: Daniel Fett;Ralf Küsters;G. Schmitz
DOI: 10.1109/asiajcis.2017.19
发表时间: 2017-08
期刊: 2017 12th Asia Joint Conference on Information Security (AsiaJCIS)
影响因子: --
作者:
J. D. Ndibwile;Y. Kadobayashi;Doudou Fall
通讯作者: J. D. Ndibwile;Y. Kadobayashi;Doudou Fall
DOI: 10.1109/sp.2015.62
发表时间: 2015-05
期刊: 2015 IEEE Symposium on Security and Privacy
影响因子: --
作者:
Antonio Bianchi;Jacopo Corbetta;L. Invernizzi;Y. Fratantonio;Christopher Krügel;Giovanni Vigna
通讯作者: Antonio Bianchi;Jacopo Corbetta;L. Invernizzi;Y. Fratantonio;Christopher Krügel;Giovanni Vigna
DOI: --
发表时间: 2016
期刊: --
影响因子: --
作者:
Ronghai Yang;W. Lau;Tianyu Liu
通讯作者: Ronghai Yang;W. Lau;Tianyu Liu
DOI: 10.1145/2818000.2818024
发表时间: 2015-12
期刊: Proceedings of the 31st Annual Computer Security Applications Conference
影响因子: --
作者:
Hui Wang;Yuanyuan Zhang;Juanru Li;Hui Liu;Wenbo Yang;Bodong Li;Dawu Gu
通讯作者: Hui Wang;Yuanyuan Zhang;Juanru Li;Hui Liu;Wenbo Yang;Bodong Li;Dawu Gu