Security Issues in OAuth 2.0 SSO Implementations

Author:

Li Wanpeng,Mitchell Chris J.

Publisher

Springer International Publishing

Reference30 articles.

1. Hardt, D.: The OAuth 2.0 authorization framework (2012), http://tools.ietf.org/html/rfc6819

2. Hanna, S., Shin, R., Akhawe, D., Boehm, A., Saxena, P., Song, D.: The emperor’s new APIs: On the (in)secure usage of new client-side primitives. In: Proc. W2SP 2010 (2010)

3. Miculan, M., Urban, C.: Formal analysis of Facebook Connect Single Sign-On authentication protocol. In: Proc. SofSem 2011, OKAT, pp. 99–116 (2011)

4. Sun, S.T., Beznosov, K.: The devil is in the (implementation) details: An empirical analysis of OAuth SSO systems. In: Yu, T., Danezis, G., Gligor, V.D. (eds.) Proc. CCS 2012, pp. 378–390. ACM (2012)

5. Wang, R., Chen, S., Wang, X.: Signing me onto your accounts through facebook and google: A traffic-guided security study of commercially deployed single-sign-on web services. In: Proc. IEEE Symp. on Security and Privacy 2012. IEEE (2012)

Cited by 35 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. CSRFing the SSO Waves: Security Testing of SSO-Based Account Linking Process;2024 IEEE 9th European Symposium on Security and Privacy (EuroS&P);2024-07-08

2. 5GAC-Analyzer: Identifying Over-Privilege Between 5G Core Network Functions;Proceedings of the 17th ACM Conference on Security and Privacy in Wireless and Mobile Networks;2024-05-27

3. A New Framework for Microservices with Single Sign-On, Security Assertion Markup Language and OpenID Connect;2024 3rd International Conference on Sentiment Analysis and Deep Learning (ICSADL);2024-03-13

4. Formal Analysis of Access Control Mechanism of 5G Core Network;Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security;2023-11-15

5. WEBAPIK: a body of structured knowledge on designing web APIs;Requirements Engineering;2023-03-14

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3