loading
  • Login
  • Sign-Up

Research.Publish.Connect.

Paper

Authors: Giada Sciarretta 1 ; Alessandro Armando 2 ; Roberto Carbone 3 and Silvio Ranise 3

Affiliations: 1 FBK-Irst and University of Trento, Italy ; 2 FBK-Irst and University of Genova, Italy ; 3 FBK-Irst, Italy

ISBN: 978-989-758-196-0

Keyword(s): Single Sign-On, Digital Identity, Security of Mobile Devices, OAuth 2.0.

Related Ontology Subjects/Areas/Topics: Data and Application Security and Privacy ; Identity Management ; Information and Systems Security ; Security and Privacy in Mobile Systems ; Security Protocols

Abstract: While there exist many secure authentication and authorization solutions for web applications, their adaptation in the mobile context is a new and open challenge. In this paper, we argue that the lack of a proper reference model for Single Sign-On (SSO) for mobile native applications drives many social network vendors (acting as Identity Providers) to develop their own mobile solution. However, as the implementation details are not well documented, it is difficult to establish the proper security level of these solutions. We thus provide a rational reconstruction of the Facebook SSO flow, including a comparison with the OAuth 2.0 standard and a security analysis obtained testing the Facebook SSO reconstruction against a set of identified SSO attacks. Based on this analysis, we have modified and generalized the Facebook solution proposing a native SSO solution capable of solving the identified vulnerabilities and accommodating any Identity Provider.

PDF ImageFull Text

Download
Sign In Guest: Register as new SCITEPRESS user or Join INSTICC now for free.

Sign In SCITEPRESS user: please login.

Sign In INSTICC Members: please login. If not a member yet, Join INSTICC now for free.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 23.20.132.227. INSTICC members have higher download limits (free membership now)

In the current month:
Recent papers: 1 available of 1 total
2+ years older papers: 2 available of 2 total

Paper citation in several formats:
Sciarretta G., Armando A., Carbone R. and Ranise S. (2016). Security of Mobile Single Sign-On: A Rational Reconstruction of Facebook Login Solution.In Proceedings of the 13th International Joint Conference on e-Business and Telecommunications - Volume 4: SECRYPT, (ICETE 2016) ISBN 978-989-758-196-0, pages 147-158. DOI: 10.5220/0005969001470158

@conference{secrypt16,
author={Giada Sciarretta and Alessandro Armando and Roberto Carbone and Silvio Ranise},
title={Security of Mobile Single Sign-On: A Rational Reconstruction of Facebook Login Solution},
booktitle={Proceedings of the 13th International Joint Conference on e-Business and Telecommunications - Volume 4: SECRYPT, (ICETE 2016)},
year={2016},
pages={147-158},
publisher={ScitePress},
organization={INSTICC},
doi={10.5220/0005969001470158},
isbn={978-989-758-196-0},
}

TY - CONF

JO - Proceedings of the 13th International Joint Conference on e-Business and Telecommunications - Volume 4: SECRYPT, (ICETE 2016)
TI - Security of Mobile Single Sign-On: A Rational Reconstruction of Facebook Login Solution
SN - 978-989-758-196-0
AU - Sciarretta G.
AU - Armando A.
AU - Carbone R.
AU - Ranise S.
PY - 2016
SP - 147
EP - 158
DO - 10.5220/0005969001470158

Sorted by: Show papers

Note: The preferred Subjects/Areas/Topics, listed below for each paper, are those that match the selected paper topics and their ontology superclasses.
More...

Login or register to post comments.

Comments on this Paper: Be the first to review this paper.

Show authors

Note: The preferred Subjects/Areas/Topics, listed below for each author, are those that more frequently used in the author's papers.
More...