{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T22:51:39Z","timestamp":1779144699589,"version":"3.51.4"},"publisher-location":"Cham","reference-count":37,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319897219","type":"print"},{"value":"9783319897226","type":"electronic"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-89722-6_8","type":"book-chapter","created":{"date-parts":[[2018,4,13]],"date-time":"2018-04-13T14:53:50Z","timestamp":1523631230000},"page":"188-213","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Design, Formal Specification and Analysis of Multi-Factor Authentication Solutions with a Single Sign-On Experience"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7567-4526","authenticated-orcid":false,"given":"Giada","family":"Sciarretta","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2853-4269","authenticated-orcid":false,"given":"Roberto","family":"Carbone","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7269-9285","authenticated-orcid":false,"given":"Silvio","family":"Ranise","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9916-271X","authenticated-orcid":false,"given":"Luca","family":"Vigan\u00f2","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,4,14]]},"reference":[{"key":"8_CR1","unstructured":"BBA \u2013 British Bankers\u2019 Association: An app-etite for banking (2017). https:\/\/www.bba.org.uk\/wp-content\/uploads\/2017\/06\/WWBN-IV.pdf"},{"key":"8_CR2","unstructured":"European Commission: mHealth (2016). https:\/\/ec.europa.eu\/digital-single-market\/en\/mhealth"},{"key":"8_CR3","unstructured":"He, D., Naveed, M., Gunter, C.A., Nahrstedt, K.: Security Concerns in Android mHealth App (2014). https:\/\/www.ncbi.nlm.nih.gov\/pmc\/articles\/PMC4419898\/"},{"key":"8_CR4","unstructured":"European Commission: Regulation EU 2016\/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/EC (General Data Protection Regulation). http:\/\/www.eugdpr.org"},{"key":"8_CR5","unstructured":"Google: Google Authenticator. https:\/\/support.google.com\/accounts\/answer\/1066447?hl=en"},{"key":"8_CR6","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1016\/j.cose.2017.04.011","volume":"F71","author":"G Sciarretta","year":"2017","unstructured":"Sciarretta, G., Carbone, R., Ranise, S., Armando, A.: Anatomy of the Facebook solution for mobile single sign-on: security assessment and improvements. J. Comput. Secur. (COSE 2017) F71, 71\u201386 (2017). https:\/\/doi.org\/10.1016\/j.cose.2017.04.011","journal-title":"J. Comput. Secur. (COSE 2017)"},{"key":"8_CR7","doi-asserted-by":"crossref","unstructured":"Sciarretta, G., Armando, A., Carbone, R., Ranise, S.: Security of mobile single sign-on: a rational reconstruction of Facebook login solution. In: Proceedings of the 13th International Joint Conference on e-Business and Telecommunications (ICETE 2016). SECRYPT, vol. 4, pp. 147\u2013158 (2016)","DOI":"10.5220\/0005969001470158"},{"key":"8_CR8","unstructured":"ECB - European Central Bank: Final guidelines on the security of Internet payments (2014). https:\/\/www.eba.europa.eu\/documents\/10180\/934179\/EBA-GL-2014-12+%28Guidelines+on+the+security+of+internet+payments%29.pdf\/f27bf266-580a-4ad0-aaec-59ce52286af0"},{"issue":"11","key":"8_CR9","doi-asserted-by":"publisher","first-page":"770","DOI":"10.1145\/358790.358797","volume":"24","author":"L Lamport","year":"1981","unstructured":"Lamport, L.: Password authentication with insecure communication communications. Commun. ACM 24(11), 770\u2013772 (1981)","journal-title":"Commun. ACM"},{"key":"8_CR10","volume-title":"Distributed Systems: Concepts and Design","author":"G Coulouris","year":"2005","unstructured":"Coulouris, G., Dollimore, J., Kindberg, T.: Distributed Systems: Concepts and Design, 4th edn. Addison-Wesley, Boston (2005)","edition":"4"},{"key":"8_CR11","unstructured":"AVANTSSAR Project: Deliverable D2.3 (update) ASLan++ specification and tutorial. http:\/\/www.avantssar.eu\/pdf\/deliverables\/avantssar-d2-3_update.pdf (2008)"},{"key":"8_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1007\/978-3-642-28756-5_19","volume-title":"Tools and Algorithms for the Construction and Analysis of Systems","author":"A Armando","year":"2012","unstructured":"Armando, A., et al.: The AVANTSSAR platform for the automated validation of trust and security of service-oriented architectures. In: Flanagan, C., K\u00f6nig, B. (eds.) TACAS 2012. LNCS, vol. 7214, pp. 267\u2013282. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-28756-5_19"},{"issue":"2","key":"8_CR13","doi-asserted-by":"publisher","first-page":"187","DOI":"10.1007\/s10009-015-0385-y","volume":"18","author":"A Armando","year":"2016","unstructured":"Armando, A., Carbone, R., Compagna, L.: SATMC: a SAT-based model checker for security protocols, business processes, and security APIs. STTT 18(2), 187\u2013204 (2016)","journal-title":"STTT"},{"key":"8_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"728","DOI":"10.1007\/978-3-642-38631-2_63","volume-title":"Network and System Security","author":"A Armando","year":"2013","unstructured":"Armando, A., Carbone, R., Zanetti, L.: Formal modeling and automatic security analysis of two-factor and two-channel authentication protocols. In: Lopez, J., Huang, X., Sandhu, R. (eds.) NSS 2013. LNCS, vol. 7873, pp. 728\u2013734. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-38631-2_63"},{"key":"8_CR15","unstructured":"OASIS: SAML V2.0 technical overview (2005). https:\/\/docs.oasis-open.org\/security\/saml\/v2.0\/saml-core-2.0-os.pdf"},{"key":"8_CR16","unstructured":"IETF: TOTP: Time-Based One-Time Password Algorithm (2011). https:\/\/tools.ietf.org\/html\/rfc6238"},{"issue":"2","key":"8_CR17","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1109\/TIT.1983.1056650","volume":"29","author":"D Dolev","year":"1983","unstructured":"Dolev, D., Yao, A.: On the security of public-key protocols. IEEE Trans. Inf. Theor. 29(2), 198\u2013208 (1983)","journal-title":"IEEE Trans. Inf. Theor."},{"key":"8_CR18","doi-asserted-by":"crossref","unstructured":"Armando, A., Carbone, R., Compagna, L., Cu\u00e9llar, J., Tobarra, L.: Formal analysis of SAML 2.0 web browser single sign-on: breaking the SAML-based single sign-on for Google Apps. In: Proceedings of the 6th ACM Workshop on Formal Methods in Security Engineering (FMSE), pp. 1\u201310 (2008)","DOI":"10.1145\/1456396.1456397"},{"key":"8_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"337","DOI":"10.1007\/978-3-642-04444-1_21","volume-title":"Computer Security \u2013 ESORICS 2009","author":"S M\u00f6dersheim","year":"2009","unstructured":"M\u00f6dersheim, S., Vigan\u00f2, L.: Secure pseudonymous channels. In: Backes, M., Ning, P. (eds.) ESORICS 2009. LNCS, vol. 5789, pp. 337\u2013354. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-04444-1_21"},{"key":"8_CR20","doi-asserted-by":"crossref","unstructured":"Lowe, G.: A hierarchy of authentication specifications. In: Proceedings of the 10th IEEE Workshop on Computer Security Foundations (1997)","DOI":"10.1109\/CSFW.1997.596782"},{"key":"8_CR21","unstructured":"IETF: The OAuth 2.0 Authorization Framework (2012). http:\/\/tools.ietf.org\/html\/rfc6749"},{"key":"8_CR22","unstructured":"OIDF: OpenID Connect Core 1.0 (2014). http:\/\/openid.net\/specs\/openid-connect-core-1_0.html"},{"key":"8_CR23","doi-asserted-by":"crossref","unstructured":"Chen, E., Pei, Y., Chen, S., Tian, Y., Kotcher, R., Tague, P.: OAuth demystified for mobile application developers. In: Proceedings of the ACM Conference on Computer and Communications Security (CCS) (2014)","DOI":"10.1145\/2660267.2660323"},{"key":"8_CR24","doi-asserted-by":"crossref","unstructured":"Shehab, M., Mohsen, F.: Towards enhancing the security of OAuth implementations in smart phones. In: IEEE International Conference on Mobile Services (MS), pp. 39\u201346 (2014)","DOI":"10.1109\/MobServ.2014.15"},{"key":"8_CR25","unstructured":"OAuth Working Group: OAuth 2.0 for Native Apps (2016). https:\/\/tools.ietf.org\/html\/rfc8252"},{"key":"8_CR26","doi-asserted-by":"crossref","unstructured":"Sun, S., Beznosov, K.: The devil is in the (implementation) details: an empirical analysis of OAuth SSO systems. In: Proceedings of the ACM Conference on Computer and Communications Security (CCS 2012) (2012)","DOI":"10.1145\/2382196.2382238"},{"key":"8_CR27","doi-asserted-by":"crossref","unstructured":"Wang, R., Chen, S., Wang, X.: Signing me onto your accounts through Facebook and Google: a traffic-guided security study of commercially deployed single-sign-on web services. In: Proceedings of the IEEE Symposium on Security and Privacy (S&P), pp. 365\u2013379 (2012)","DOI":"10.1109\/SP.2012.30"},{"key":"8_CR28","doi-asserted-by":"crossref","unstructured":"Sudhodanan, A., Armando, A., Carbone, R., Compagna, L.: Attack patterns for black-box security testing of multi-party web applications. In: Proceedings of the 23rd Annual Network and Distributed System Security Symposium (NDSS) (2016)","DOI":"10.14722\/ndss.2016.23286"},{"key":"8_CR29","unstructured":"Yang, R., Lau, W.C., Liu, T.: Signing into one billion mobile app accounts effortlessly with OAuth2.0. In: Black Hat Europe (2016)"},{"key":"8_CR30","doi-asserted-by":"crossref","unstructured":"Fett, D., K\u00fcsters, R., Schmitz, G.: A comprehensive formal security analysis of OAuth 2.0. In: Proceedings of the 23rd ACM SIGSAC Conference on Computer and Communications Security (CCS), pp. 1204\u20131215. ACM (2016)","DOI":"10.1145\/2976749.2978385"},{"key":"8_CR31","doi-asserted-by":"crossref","unstructured":"Fett, D., K\u00fcsters, R., Schmitz, G.: An expressive model for the web infrastructure: definition and application to the BrowserID SSO system. In: Proceedings of the 35th IEEE Symposium on Security and Privacy (S&P), pp. 673\u2013688. IEEE Computer Society (2014)","DOI":"10.1109\/SP.2014.49"},{"key":"8_CR32","doi-asserted-by":"crossref","unstructured":"Fett, D., K\u00fcsters, R., Schmitz, G.: The web SSO standard OpenID connect: in-depth formal security analysis and security guidelines. In: Proceedings of the 30th Computer Security Foundations Symposium (CSF). IEEE Computer Society (2017)","DOI":"10.1109\/CSF.2017.20"},{"key":"8_CR33","doi-asserted-by":"crossref","unstructured":"Bansal, C., Bhargavan, K., Maffeis, S.: Discovering concrete attacks on website authorization by formal analysis. In: Proceedings of 25th IEEE Computer Security Foundations Symposium (CSF 2012), pp. 247\u2013262 (2012)","DOI":"10.1109\/CSF.2012.27"},{"key":"8_CR34","doi-asserted-by":"crossref","unstructured":"Pai, S., Sharma, Y., Kumar, S., Pai, R.M., Singh, S.: Formal verification of OAuth 2.0 using alloy framework. In: Proceedings of the IEEE International Conference on Communication Systems and Network Technologies (CSNT), pp. 655\u2013659 (2011)","DOI":"10.1109\/CSNT.2011.141"},{"key":"8_CR35","doi-asserted-by":"crossref","unstructured":"Yan, H., Fang, H., Kuka, C., Zhu, H.: Verification for OAuth using ASLan++. In: Proceedings of 16th IEEE International Symposium on High Assurance Systems Engineering HASE, pp. 76\u201384 (2015)","DOI":"10.1109\/HASE.2015.20"},{"key":"8_CR36","doi-asserted-by":"crossref","unstructured":"Ye, Q., Bai, G., Wang, K., Dong, J.S.: Formal analysis of a single sign-on protocol implementation for Android. In: Proceedings of the 20th ICECCS, pp. 90\u201399 (2015)","DOI":"10.1109\/ICECCS.2015.20"},{"key":"8_CR37","unstructured":"Yubico: YubiKey NEO. https:\/\/www.yubico.com\/products\/yubikey-hardware\/yubikey-neo"}],"container-title":["Lecture Notes in Computer Science","Principles of Security and Trust"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-89722-6_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,10,31]],"date-time":"2020-10-31T18:56:01Z","timestamp":1604170561000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-89722-6_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319897219","9783319897226"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-89722-6_8","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]}}}