SSOme: Securing Advanced Single Sign-On in a Modern Ecosystem
SSOme: Securing Advanced Single Sign-On in a Modern Ecosystem
批准号:
443324941
负责人:
Professor Dr. Ralf Küsters
金额:
$0.0万
依托单位国家:
德国
项目类别:
Research Grants
财政年份:
--
资助国家:
德国
项目状态:
未结题
起止时间:
中文摘要
在社交网络的推动下,单点登录(SSO)在网络上变得非常流行。使用SSO方案,用户只需在他们的电子邮件提供商或最喜欢的社交网络上登录,例如,通过“登录Facebook”或“登录Google”,就可以方便地登录到许多网站。他们还可以授予第三方访问他们账户的权限,例如,允许这些方在他们的Facebook时间表上发布内容。这些单点登录方案通常基于联合认证和授权协议,如OAuth 2.0和OpenID Connection。在我们之前的研究中,我们开发了一个丰富的Web基础设施模型,并成功地将其应用于分析基于Web的单点登录方案。我们的分析揭示了几个针对广泛使用的标准的新攻击,如OAuth 2.0和OpenID Connect。我们还提出了修复建议,这些修复在我们的模型中被证明是安全的,并导致了标准的改进。然而,目前单点登录系统的应用环境正在迅速变化和扩大。单点登录系统现在发现越来越多的应用在纯Web环境之外,以及在高风险和高风险的环境中。例如,银行已经开始使用单点登录技术,使它们的服务可以在线提供,并通过互联网相互连接。自2019年9月起,欧盟的银行有法律义务向第三方服务开放其系统,例如支付处理器,这些服务可能会代表用户查看或调用交易。单点登录系统和标准现在也被用于物联网设备,如门锁和汽车,例如,用户可以授权其他用户,如朋友或送货服务,打开他们的前门或汽车。此外,正在建立基于SSO的系统,以供医生向患者开出数字处方或建立具有法律约束力的合同,例如与保险公司,用户向其银行进行身份验证以生成数字签名。这些新的用例引发了新标准、协议和系统的开发。一些新应用程序的高风险性质、处理的敏感信息以及这些协议和SSO系统应该在其中运行的新环境,使得以前的方法不足以进行正式的安全和隐私分析。因此,为新的和先进的单点登录系统和标准的形式化分析提供合适的模型和方法,对相关的新兴标准和应用进行分析,为新的高风险和敏感的生态系统设计安全的单点登录系统,是本项目的主要目标。
英文摘要
Driven by social networks, single sign-on (SSO) has become extremely popular on the web. Using SSO schemes, users can conveniently sign in at many web sites by just signing in at their email provider or favorite social network, for example, via "Login with Facebook" or "Login with Google". They can also grant third parties access to their accounts, allowing these parties, for example, to post content to their Facebook timeline. These SSO schemes are typically based on federated authentication and authorization protocols, such as OAuth 2.0 and OpenID Connect.In our previous research, we have developed a rich model of the web infrastructure and successfully applied it to analyze web-based SSO schemes. Our analysis has revealed several new attacks on widely used standards, such as OAuth 2.0 and OpenID Connect. We also suggested fixes, which we proved secure in our model and which have led to improvements of the standards.Currently, the landscape of applications of SSO systems is, however, changing and expanding rapidly. SSO systems now find more and more applications outside of the pure web context as well as in high-risk and high-stake environments. For example, banks have started to employ SSO technologies to make their services available online and to interconnect them over the Internet. Since September 2019, banks in the EU are legally obliged to open their systems to third-party services, such as payment processors, that may view or invoke transactions on the users' behalf. SSO systems and standards are now also employed for IoT devices, such as door locks and cars, where, for example, users can authorize other users, such as friends or delivery services, to open their front doors or cars. Moreover, SSO-based systems are being built for physicians to issue digital prescriptions to patients or for establishing legally binding contracts, for example, with insurance companies, with users authenticating to their banks in order to generate digital signatures.Such new use cases have sparked the development of new standards, protocols, and systems. The high-risk nature of some of the new applications, the sensible information processed, and the new contexts in which these protocols and SSO systems are supposed to function, render previous approaches for the formal security and privacy analysis insufficient. Among others, stronger and new security and privacy properties as well as new and more suitable and realistic attacker models are required.Providing appropriate models and methods for the formal analysis of the new and advanced SSO systems and standards, carrying out such an analysis on relevant emerging standards and applications, and designing secure SSO systems for the new high-risk and sensitive ecosystems are therefore the main goals of this project.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
A Mechanized Rich Model of the Web Infrastructure
-
批准号:276807658
-
项目类别:Research Grants
-
资助金额:$0.0万
-
财政年份:2015
-
负责人:Professor Dr. Ralf Küsters
-
依托单位:
Utilizing Simulation-Based Security for the Modular Cryptographic Analysis of Real-World Key Exchange and Secure Channel Protocols
-
批准号:250008536
-
项目类别:Research Grants
-
资助金额:$0.0万
-
财政年份:2013
-
负责人:Professor Dr. Ralf Küsters
-
依托单位:
Implementation-Level Analysis of E-Voting Systems
-
批准号:183816017
-
项目类别:Priority Programmes
-
资助金额:$0.0万
-
财政年份:2010
-
负责人:Professor Dr. Ralf Küsters
-
依托单位:
Formale und kryptographische Analyse von Protokollen mit spieltheoretischen Sicherheitsanforderungen
-
批准号:88943336
-
项目类别:Research Grants
-
资助金额:$0.0万
-
财政年份:2008
-
负责人:Professor Dr. Ralf Küsters
-
依托单位:
Automatische Analyse kryptographischer Protokolle mit komplexen Nachrichtenformaten
-
批准号:5445829
-
项目类别:Research Grants
-
资助金额:$0.0万
-
财政年份:2005
-
负责人:Professor Dr. Ralf Küsters
-
依托单位:
Automatische Verifikation kryptographischer Protokolle
-
批准号:5402449
-
项目类别:Research Fellowships
-
资助金额:$0.0万
-
财政年份:2003
-
负责人:Professor Dr. Ralf Küsters
-
依托单位:
Post-Quantum Secure Verifiable Tally-Hiding Remote E-Voting
-
批准号:411720488
-
项目类别:Research Grants
-
资助金额:$0.0万
-
财政年份:--
-
负责人:Professor Dr. Ralf Küsters
-
依托单位:
CADL: Composable Accountability for Distributed Ledgers
-
批准号:459731562
-
项目类别:Research Grants
-
资助金额:$0.0万
-
财政年份:--
-
负责人:Professor Dr. Ralf Küsters
-
依托单位:
海外基金