Skip to main content

2013 | OriginalPaper | Buchkapitel

Security Challenges of Current Federated eID Architectures

verfasst von : Libor Neumann

Erschienen in: ISSE 2013 Securing Electronic Business Processes

Verlag: Springer Fachmedien Wiesbaden

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

The paper deals with security analysis of target assets protection in IT systems using federated eID technologies.
The main topic of the analysis is asset protection in a target IT system using federated eID system for IAM (Identity and Access Management), particularly for authentication.
The analysis deals with the well-known federated eID technologies i.e. oAuth, OpenId, SAML, SCIM, WS-federation and WS-trust.
The issue of relationship between target system data channel (data channel between authenticated user and target system) and authentication result of federated eID system (assertion) is analysed.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
[AlWZ10]
Zurück zum Zitat Altman, J., Williams, N., Zhu, L.: RFC 5929, Channel Bindings for TLS, Internet Engineering Task Force (IETF), July 2010 Altman, J., Williams, N., Zhu, L.: RFC 5929, Channel Bindings for TLS, Internet Engineering Task Force (IETF), July 2010
[Badr09]
Zurück zum Zitat Badra, M.: RFC 5487, Pre-Shared Key Cipher Suites for TLS with SHA-256/384 and AES Galois Counter Mode, IETF Trust, March 2009 Badra, M.: RFC 5487, Pre-Shared Key Cipher Suites for TLS with SHA-256/384 and AES Galois Counter Mode, IETF Trust, March 2009
[Barnll]
Zurück zum Zitat Barnes, R.: RFC 6394,..Use Cases and Requirements for DNS-Based Authentication of Named Entities (DANE)", IETF, October 2011 Barnes, R.: RFC 6394,..Use Cases and Requirements for DNS-Based Authentication of Named Entities (DANE)", IETF, October 2011
[BlGo07]
Zurück zum Zitat Blumenthal, U., Goel, P.: RFC 4785, Pre-Shared Key (PSK) Ciphersuites with NULL Encryption for Transport Layer Security (TLS), The IETF Trust, January 2007 Blumenthal, U., Goel, P.: RFC 4785, Pre-Shared Key (PSK) Ciphersuites with NULL Encryption for Transport Layer Security (TLS), The IETF Trust, January 2007
[BrHo10]
Zurück zum Zitat Brown, M., Housley, R.: RFC 5878, Transport Layer Security (TLS) Authorization Extensions, IETF Trust, May 2010 Brown, M., Housley, R.: RFC 5878, Transport Layer Security (TLS) Authorization Extensions, IETF Trust, May 2010
[DiRe06]
Zurück zum Zitat Dierks, T., Rescorla, E.: RFC 4346, The Transport Layer Security (TLS) Protocol Version 1.1, The Internet Society, April 2006 Dierks, T., Rescorla, E.: RFC 4346, The Transport Layer Security (TLS) Protocol Version 1.1, The Internet Society, April 2006
[DiRe08]
Zurück zum Zitat Dierks, T., Rescorla, E.: RFC 5246, The Transport Layer Security (TLS) Protocol Version 1.2, The IETF Trust, August 2008 Dierks, T., Rescorla, E.: RFC 5246, The Transport Layer Security (TLS) Protocol Version 1.2, The IETF Trust, August 2008
[Hard12]
Zurück zum Zitat D. Hardt, Ed.:..The OAuth 2.0 Authorization Framework", Internet Engineering Task Force (IETF), Request for Comments: 6749, October 2012 D. Hardt, Ed.:..The OAuth 2.0 Authorization Framework", Internet Engineering Task Force (IETF), Request for Comments: 6749, October 2012
[ErTs05]
Zurück zum Zitat Eronen, P., Tschofenig, H.: RFC 4279, Pre-Shared Key Ciphersuites for Transport Layer Security (TLS), The Internet Society, December 2005 Eronen, P., Tschofenig, H.: RFC 4279, Pre-Shared Key Ciphersuites for Transport Layer Security (TLS), The Internet Society, December 2005
[FrKK11]
Zurück zum Zitat Freier, A., Karlton, P., Kocher, P.: RFC 6101, The Secure Sockets Layer (SSL) Protocol Version 3.0, IETF, August 2011 Freier, A., Karlton, P., Kocher, P.: RFC 6101, The Secure Sockets Layer (SSL) Protocol Version 3.0, IETF, August 2011
[FuBl08]
Zurück zum Zitat Funk, P., Blake-Wilson, S.: RFC 5281, Extensible Authentication Protocol Tunneled Transport Layer Security Authenticated Protocol Version 0 (EAP-TTLSv0), The IETF Trust , August 2008 Funk, P., Blake-Wilson, S.: RFC 5281, Extensible Authentication Protocol Tunneled Transport Layer Security Authenticated Protocol Version 0 (EAP-TTLSv0), The IETF Trust , August 2008
[HaFu07]
Zurück zum Zitat Hanna, Steve, Funk, Paul: draft - Key Agility Extensions for EAP-TTLSv0, The IETF Trust, September 24, 2007 Hanna, Steve, Funk, Paul: draft - Key Agility Extensions for EAP-TTLSv0, The IETF Trust, September 24, 2007
[Hoff12]
Zurück zum Zitat Hoffman, P.: RFC 6358,..Additional Master Secret Inputs for TLS", IETF, January 2012 Hoffman, P.: RFC 6358,..Additional Master Secret Inputs for TLS", IETF, January 2012
[HoJB12]
Zurück zum Zitat Hodges, J., Jackson, C., Barth, A.: RFC 6797,..HTTP Strict Transport Security (HSTS)", IETF, November 2012 Hodges, J., Jackson, C., Barth, A.: RFC 6797,..HTTP Strict Transport Security (HSTS)", IETF, November 2012
[HoSc12]
Zurück zum Zitat Hoffman, P., Schlyter, J.: RFC 6698,..The DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) Protocol: TLSA", IETF, August 2012 Hoffman, P., Schlyter, J.: RFC 6698,..The DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) Protocol: TLSA", IETF, August 2012
[Jose11]
Zurück zum Zitat Josefsson, S.: RFC 6251,.Using Kerberos Version 5 over the Transport Layer Security (TLS) Protocol", IETF, May 2011 Josefsson, S.: RFC 6251,.Using Kerberos Version 5 over the Transport Layer Security (TLS) Protocol", IETF, May 2011
[Kero10]
Zurück zum Zitat Keromytis, A.: RFC 6042, Transport Layer Security (TLS) Authorization Using KeyNote, IETF Trust , October 2010 Keromytis, A.: RFC 6042, Transport Layer Security (TLS) Authorization Using KeyNote, IETF Trust , October 2010
[MaGi11]
Zurück zum Zitat Mavrogiannopoulos, N., Gillmor, D.: RFC 6091, Using OpenPGP Keys for Transport Layer Security (TLS) Authentication, IETF Trust, February 2011 Mavrogiannopoulos, N., Gillmor, D.: RFC 6091, Using OpenPGP Keys for Transport Layer Security (TLS) Authentication, IETF Trust, February 2011
[MeHu99]
Zurück zum Zitat Medvinsky, A., Hur, M.: RFC 2712, Addition of Kerberos Cipher Suites to Transport Layer Security (TLS), The Internet Society, October 1999 Medvinsky, A., Hur, M.: RFC 2712, Addition of Kerberos Cipher Suites to Transport Layer Security (TLS), The Internet Society, October 1999
[Neum07]
Zurück zum Zitat Neumann, Libor: An analysis of e-identity organizational and technological solutions within a single European information space. In: e-Challenges e-2007, The Hague, Netherlands, 2007, pp. 1326-1333. Neumann, Libor: An analysis of e-identity organizational and technological solutions within a single European information space. In: e-Challenges e-2007, The Hague, Netherlands, 2007, pp. 1326-1333.
[Neum08]
Zurück zum Zitat Neumann, Libor: Anonymous, Liberal, and User-Centric Electronic Identity - A New, Systematic Design of eID Infrastructure, In: e-Challenges e-2008, 22-24 October 2008, Stockholm, Sweden. Neumann, Libor: Anonymous, Liberal, and User-Centric Electronic Identity - A New, Systematic Design of eID Infrastructure, In: e-Challenges e-2008, 22-24 October 2008, Stockholm, Sweden.
[Neum12]
Zurück zum Zitat Neumann, Libor et al.: Strong Authentication of Humans and Machines in Policy Controlled Cloud Computing Environment Using Automatic Cyber Identity, In: ISSE 2012 Securing Electronic Business Processes, Highlights of the Information Security Solutions Europe 2012 Conference, Springer Vieweg, 2012, pp 195-206. Neumann, Libor et al.: Strong Authentication of Humans and Machines in Policy Controlled Cloud Computing Environment Using Automatic Cyber Identity, In: ISSE 2012 Securing Electronic Business Processes, Highlights of the Information Security Solutions Europe 2012 Conference, Springer Vieweg, 2012, pp 195-206.
[NiAT02]
Zurück zum Zitat Niemi, A., Arkko, J., Torvinen, V.: RFC 3310, Hypertext Transfer Protocol (HTTP) Digest Authentication Using Authentication and Key Agreement (AKA), The Internet Society, September 2002 Niemi, A., Arkko, J., Torvinen, V.: RFC 3310, Hypertext Transfer Protocol (HTTP) Digest Authentication Using Authentication and Key Agreement (AKA), The Internet Society, September 2002
[Open07]
Zurück zum Zitat OpenID: „OpenID Authentication 2.0 - Final", December 5, 2007 OpenID: „OpenID Authentication 2.0 - Final", December 5, 2007
[OASI05a]
Zurück zum Zitat OASIS: „Profiles for the OASIS Security Assertion Markup Language (SAML)V2.0", OASIS Standard, 15 March 2005 OASIS: „Profiles for the OASIS Security Assertion Markup Language (SAML)V2.0", OASIS Standard, 15 March 2005
[OASI05b]
Zurück zum Zitat OASIS: „Security and Privacy Considerations for the OASIS Security Assertion Markup Language (SAML) V2.0", OASIS Standard, 15 March 2005 OASIS: „Security and Privacy Considerations for the OASIS Security Assertion Markup Language (SAML) V2.0", OASIS Standard, 15 March 2005
[OASI07]
Zurück zum Zitat OASIS: „WS-Trust 1.3", OASIS Standard, 19 March 2007 OASIS: „WS-Trust 1.3", OASIS Standard, 19 March 2007
[OASI08]
Zurück zum Zitat OASIS: „Security Assertion Markup Language (SAML) V2.0 Technical Overview", Committee Draft 02, 25 March 2008 OASIS: „Security Assertion Markup Language (SAML) V2.0 Technical Overview", Committee Draft 02, 25 March 2008
[OASI09]
Zurück zum Zitat OASIS: „Web Services Federation Language (WS-Federation) Version 1.2", OASIS Standard, 22 May 2009 OASIS: „Web Services Federation Language (WS-Federation) Version 1.2", OASIS Standard, 22 May 2009
[OASI10]
Zurück zum Zitat OASIS: „SAML V2.0 Holder-of-Key Web Browser SSO Profile Version 1.0", Committee Specification 02, 10 August 2010 OASIS: „SAML V2.0 Holder-of-Key Web Browser SSO Profile Version 1.0", Committee Specification 02, 10 August 2010
[OASI12]
Zurück zum Zitat OASIS: „SAML V2.0 Kerberos Web Browser SSO Profile Version 1.0", Committee Specification 01, 07 February 2012 OASIS: „SAML V2.0 Kerberos Web Browser SSO Profile Version 1.0", Committee Specification 01, 07 February 2012
[Resc10]
Zurück zum Zitat Rescorla, E.: RFC 5705, Keying Material Exporters for Transport Layer Security (TLS), IETF Trust, March 2010 Rescorla, E.: RFC 5705, Keying Material Exporters for Transport Layer Security (TLS), IETF Trust, March 2010
[SaMB06]
Zurück zum Zitat Santesson, S., Medvinsky, A., Ball, J.: RFC 4681, TLS User Mapping Extension, The Internet Society, October 2006 Santesson, S., Medvinsky, A., Ball, J.: RFC 4681, TLS User Mapping Extension, The Internet Society, October 2006
[Sant06]
Zurück zum Zitat Santesson, S.: RFC 4680, TLS Handshake Message for Supplemental Data, The Internet Society, September 2006 Santesson, S.: RFC 4680, TLS Handshake Message for Supplemental Data, The Internet Society, September 2006
[SiAH08]
Zurück zum Zitat Simon, D., Aboba, B., Hurst, R.: RFC 5216, The EAP-TLS Authentication Protocol, The IETF Trust, March 2008 Simon, D., Aboba, B., Hurst, R.: RFC 5216, The EAP-TLS Authentication Protocol, The IETF Trust, March 2008
[ToAN05]
Zurück zum Zitat Torvinen, V., Arkko, J., Naslund, M.: RFC 4169, Hypertext Transfer Protocol (HTTP) Digest Authentication Using Authentication and Key Agreement (AKA) Version-2, The Internet Society, November 2005 Torvinen, V., Arkko, J., Naslund, M.: RFC 4169, Hypertext Transfer Protocol (HTTP) Digest Authentication Using Authentication and Key Agreement (AKA) Version-2, The Internet Society, November 2005
[TuPo11]
Zurück zum Zitat Turner, S., Polk, T.: RFC 6176,..Prohibiting Secure Sockets Layer (SSL) Version 2.0", IETF, March 2011 Turner, S., Polk, T.: RFC 6176,..Prohibiting Secure Sockets Layer (SSL) Version 2.0", IETF, March 2011
[TWMP07]
Zurück zum Zitat Taylor, D., Wu, T., Mavrogiannopoulos, N., Perrin, T.: RFC 5054, Using the Secure Remote Password (SRP) Protocol for TLS Authentication, The IETF Trust, November 2007 Taylor, D., Wu, T., Mavrogiannopoulos, N., Perrin, T.: RFC 5054, Using the Secure Remote Password (SRP) Protocol for TLS Authentication, The IETF Trust, November 2007
[WiBu11]
Zurück zum Zitat William E. Burr, et al.: „Electronic Authentication Guideline", Special Publication 800-63-1, NIST- National Institute of Standards and Technology, December 2011 William E. Burr, et al.: „Electronic Authentication Guideline", Special Publication 800-63-1, NIST- National Institute of Standards and Technology, December 2011
[Will07]
Zurück zum Zitat Williams N.: - RFC 5056, On the Use of Channel Bindings to Secure Channels, The IETF Trust, November 2007. Williams N.: - RFC 5056, On the Use of Channel Bindings to Secure Channels, The IETF Trust, November 2007.
[WMVW12]
Zurück zum Zitat Winter, S., McCauley, M., Venaas, S., Wierenga, K.: RFC 6614, „Transport Layer Security (TLS) Encryption for RADIUS",IETF, May 2012 Winter, S., McCauley, M., Venaas, S., Wierenga, K.: RFC 6614, „Transport Layer Security (TLS) Encryption for RADIUS",IETF, May 2012
Metadaten
Titel
Security Challenges of Current Federated eID Architectures
verfasst von
Libor Neumann
Copyright-Jahr
2013
Verlag
Springer Fachmedien Wiesbaden
DOI
https://doi.org/10.1007/978-3-658-03371-2_3