Comprehensive Security Analysis of Federated Identity Management
Ключевые слова:
Federated Identity Management, SAML, OAuth, OpenID, Server Side Request Forgery, Denial-of-Service, Phishing attacksАннотация
Analyzing the security of FIdM is a challenging task, on one hand due to the various modes and options that the protocols provide, and on the other hand due to the inherent complexity of the web. A thorough understanding of the security vulnerabilities is required to remodel a stable and secure authentication system. In this paper the challenges and requirements of securing the exchange of information between enterprises have been reported. The goal of this work is to provide an in-depth security analysis of FIdM protocols. The major FIdM protocols SAML, OpenID and OAuth have been discussed. A narrative of the major security attacks and flaws in existing Federated Identity Management have been presented. The paper explores solutions to resolve the security issues reported in existing FIdM and defines a number of possible countermeasures.Cite this ArticleGargi Amoli, Manish Kala, JitendraChaurasia. A Comprehensive SecurityAnalysis of Federated IdentityManagement. Journal of CommunicationEngineering & Systems. 2017; 7(1):11–16p.Опубликован
Выпуск
Раздел
Лицензия
Declaration and Copyright Transfer Form
(to be completed by authors)
I/ We, the undersigned author(s) of the manuscript entitled ‘______________’, hereby declare, that the above manuscript which is submitted for publication in the Journal, is not published already in part or whole (except in the form of abstract) in any journal or magazine for private or public circulation, and, is not under consideration of publication elsewhere.
I/ We have read the final version of the manuscript and am/ are responsible for the thought contents embodied in it. The work dealt in the manuscript is my/ our own, and my/ our individual contribution to this work is significant enough to qualify for authorship. We also agree to the authorship of the article in the following order:
Author’s name Signature (s)
1. ________________
2. ________________
3. ________________
4. ________________