Publication | Closed Access
Stronger TLS bindings for SAML assertions and SAML artifacts
16
Citations
11
References
2008
Year
Unknown Venue
Cryptographic PrimitiveEngineeringInformation SecurityVerificationStronger Tls BindingsCryptographic ProtocolTls Security LayerSoftware AnalysisFormal VerificationHardware SecuritySecure ProtocolAttack ScenariosPublic Key InfrastructureInternet SecuritySecurity TestingComputer ScienceData SecurityCryptographySoftware SecurityFormal MethodsSaml Artifacts
Based on recently proposed attack scenarios, we show that SAML assertions and SAML artifacts are still vulnerable to real-world attacks on browser-based implementations. We propose two different bindings of SAML assertions and SAML artifacts to the TLS security layer and show that these bindings protect against all known attacks. The two bindings are based on TLS client certificates, and on a variant of the well-known Same Origin Policy of browsers.
| Year | Citations | |
|---|---|---|
Page 1
Page 1