Istituto di Scienza e Tecnologie dell'Informazione     
ter Beek M. H., Moiso C., Petrocchi M. Towards security analyses of an identity federation protocol for Web services in convergent networks. In: 3rd Advanced International Conference on Telecommunications. AICT'07 (Mauritius, 13-19 Maggio 2007). Proceedings, pp. 1 - 6. IEEE Computer Society, Los Alamitos, CA, 2007.
We describe a formal approach to the analysis of security aspects of an identity federation protocol for web services in convergent networks. This network protocol was proposed by Telecom Italia as a solution to allow end users to access services on the web through different access networks without explicitly providing any credentials, while the service providers can trust the user's identity information provided by the access networks and access some user data. As a first step towards a fullblown formal security analysis of the protocol, we specify three user scenarios in the process algebra Crypto-CCS and verify the vulnerability of one of these specifications w.r.t. a man-in-themiddle attack with the model checker PaMoChSA.
URL: http://doi.ieeecomputersociety.org/10.1109/AICT.2007.46
Subject Security
Model checking
Convergent networks
D.2.4 Software/Program Verification. Formal methods
D.2.4 Software/Program Verification. Model checking
D.4.6 Security and Protection. Verification

Icona documento 1) Download Document PDF

Icona documento Open access Icona documento Restricted Icona documento Private


Per ulteriori informazioni, contattare: Librarian http://puma.isti.cnr.it

Valid HTML 4.0 Transitional