Origin-Bound Certificates: A Fresh Approach to Strong Client Authentication for the Web.

Security'12: Proceedings of the 21st USENIX conference on Security symposium(2012)

引用 36|浏览63
暂无评分
摘要
Client authentication on the web has remained in the internet-equivalent of the stone ages for the last two decades. Instead of adopting modern public-key-based authentication mechanisms, we seem to be stuck with passwords and cookies. In this paper, we propose to break this stalemate by presenting a fresh approach to public-key-based client authentication on the web. We describe a simple TLS extension that allows clients to establish strong authenticated channels with servers and to bind existing authentication tokens like HTTP cookies to such channels. This allows much of the existing infrastructure of the web to remain unchanged, while at the same time strengthening client authentication considerably against a wide range of attacks. We implemented our system in Google Chrome and Google's web serving infrastructure, and provide a performance evaluation of this implementation.
更多
查看译文
关键词
client authentication,authentication token,modern public-key-based authentication mechanism,public-key-based client authentication,Google Chrome,existing infrastructure,fresh approach,performance evaluation,simple TLS extension,stone age,Origin-bound certificate,strong client authentication
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要