Knowledge Resource Center for Ecological Environment in Arid Area
Formal Analysis of Information Card Federated Identity-Management Protocol | |
Wang Juan1,2; Hu Hongxin3; Zhao Bo1,2; Yan Fei1,2; Zhang Huanguo1,2; Wu Qianhong1,2 | |
通讯作者 | Wang Juan |
来源期刊 | CHINESE JOURNAL OF ELECTRONICS
![]() |
ISSN | 1022-4653 |
EISSN | 2075-5597 |
出版年 | 2013 |
卷号 | 22期号:1页码:83-88 |
英文摘要 | Information Card (InfoCard) is a user-centric identity management metasystem. It has been accepted as a standard of OASIS Identity Metasystem Interoperability Technical Committee. However, there is currently a lack of security analysis to InfoCard protocol, especially, with formal methods. In this paper, we accommodate such a requirement by analyzing security properties of InfoCard protocol adopting a formal protocol analysis tool. Our analysis result discovers that current InfoCard protocol is vulnerable against the session replay attack. Furthermore, we reveal the importance of two optional elements in InfoCard metasystem, token scope and proof key, and found that InfoCard protocol will be susceptible to man-in-the-middle attack and token replay attack if these two optional elements lack. |
英文关键词 | Information card User-centric Identity Automated validation of Internet security protocols and applications (AVISPA) |
类型 | Article |
语种 | 英语 |
国家 | Peoples R China ; USA |
收录类别 | SCI-E |
WOS记录号 | WOS:000317701800016 |
WOS关键词 | SECURITY |
WOS类目 | Engineering, Electrical & Electronic |
WOS研究方向 | Engineering |
来源机构 | Arizona State University |
资源类型 | 期刊论文 |
条目标识符 | http://119.78.100.177/qdio/handle/2XILL650/176393 |
作者单位 | 1.Wuhan Univ, Comp Sch, Wuhan 430072, Peoples R China; 2.Minist Educ, Key Lab Aerosp Informat Secur & Trusted Comp, Wuhan 430072, Peoples R China; 3.Arizona State Univ, SEFCOM, Tempe, AZ 85287 USA |
推荐引用方式 GB/T 7714 | Wang Juan,Hu Hongxin,Zhao Bo,et al. Formal Analysis of Information Card Federated Identity-Management Protocol[J]. Arizona State University,2013,22(1):83-88. |
APA | Wang Juan,Hu Hongxin,Zhao Bo,Yan Fei,Zhang Huanguo,&Wu Qianhong.(2013).Formal Analysis of Information Card Federated Identity-Management Protocol.CHINESE JOURNAL OF ELECTRONICS,22(1),83-88. |
MLA | Wang Juan,et al."Formal Analysis of Information Card Federated Identity-Management Protocol".CHINESE JOURNAL OF ELECTRONICS 22.1(2013):83-88. |
条目包含的文件 | 条目无相关文件。 |
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。