{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T22:51:40Z","timestamp":1779144700207,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","license":[{"start":{"date-parts":[[2014,11,7]],"date-time":"2014-11-07T00:00:00Z","timestamp":1415318400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100002765","name":"Bundesministerium fur Wirtschaft und Technologie","doi-asserted-by":"publisher","award":["FKZ: 01MD11030"],"award-info":[{"award-number":["FKZ: 01MD11030"]}],"id":[{"id":"10.13039\/501100002765","id-type":"DOI","asserted-by":"publisher"}]},{"name":"This work has been funded by the European Union within the European Regional Development Fund program."}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2014,11,7]]},"DOI":"10.1145\/2664168.2664172","type":"proceedings-article","created":{"date-parts":[[2014,11,7]],"date-time":"2014-11-07T17:10:54Z","timestamp":1415380254000},"page":"93-104","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["Your Software at my Service"],"prefix":"10.1145","author":[{"given":"Christian","family":"Mainka","sequence":"first","affiliation":[{"name":"Horst Goertz Institute for IT-Security, Ruhr-University Bochum, Bochum, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vladislav","family":"Mladenov","sequence":"additional","affiliation":[{"name":"Horst Goertz Institute for IT-Security, Ruhr-University Bochum, Bochum, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Florian","family":"Feldmann","sequence":"additional","affiliation":[{"name":"Horst Goertz Institute for IT-Security, Ruhr-University Bochum, Bochum, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Julian","family":"Krautwald","sequence":"additional","affiliation":[{"name":"Horst Goertz Institute for IT-Security, Ruhr-University Bochum, Bochum, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"J\u00f6rg","family":"Schwenk","sequence":"additional","affiliation":[{"name":"Horst Goertz Institute for IT-Security, Ruhr-University Bochum, Bochum, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2014,11,7]]},"reference":[{"key":"e_1_3_2_1_1_1","first-page":"68","volume-title":"SEC","author":"Armando Alessandro","year":"2011"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1456396.1456397"},{"key":"e_1_3_2_1_3_1","unstructured":"Armando Alessandro and Carbone Roberto and Compagna Luca and Cu\u00e9llar Jorge and Tobarra M. Llanos. SAML: CVE-2008--3891. http:\/\/www.cvedetails.com September 2008.  Armando Alessandro and Carbone Roberto and Compagna Luca and Cu\u00e9llar Jorge and Tobarra M. Llanos. SAML: CVE-2008--3891. http:\/\/www.cvedetails.com September 2008."},{"key":"e_1_3_2_1_4_1","volume-title":"NDSS","author":"Bai Guangdong","year":"2013"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"crossref","unstructured":"A. Barth. HTTP State Management Mechanism. RFC 6265 (Proposed Standard) April 2011.  A. Barth. HTTP State Management Mechanism. RFC 6265 (Proposed Standard) April 2011.","DOI":"10.17487\/rfc6265"},{"key":"e_1_3_2_1_6_1","unstructured":"Bitium. Bitium Partners 2014. {online} https:\/\/www.bitium.com\/site\/apps\/.  Bitium. Bitium Partners 2014. {online} https:\/\/www.bitium.com\/site\/apps\/."},{"key":"e_1_3_2_1_7_1","unstructured":"Scott Cantor John Kemp Rob Philpott and Eve Maler. Profiles for the OASIS Security Assertion Markup Language (SAML) V2.0. OASIS Standard 15.03.2005 2005. http:\/\/docs.oasis-open.org\/security\/saml\/v2.0\/saml-profiles-2.0-os.pdf.  Scott Cantor John Kemp Rob Philpott and Eve Maler. Profiles for the OASIS Security Assertion Markup Language (SAML) V2.0. OASIS Standard 15.03.2005 2005. http:\/\/docs.oasis-open.org\/security\/saml\/v2.0\/saml-profiles-2.0-os.pdf."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/11751595_54"},{"key":"e_1_3_2_1_9_1","unstructured":"Clarizen. Clarizen - The way to work 2014. {online} http:\/\/www.clarizen.com\/.  Clarizen. Clarizen - The way to work 2014. {online} http:\/\/www.clarizen.com\/."},{"key":"e_1_3_2_1_10_1","unstructured":"CloudReviews 2014"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICWS.2013.72"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.5555\/956415.956441"},{"key":"e_1_3_2_1_13_1","volume-title":"IBM Research, 2006","author":"Gro\u00df Thomas","year":"2006"},{"key":"e_1_3_2_1_14_1","unstructured":"Frederick Hirsch David Solo Joseph Reagle Donald Eastlake and Thomas Roessler. XML Signature Syntax and Processing (Second Edition). W3C recommendation W3C June 2008.  Frederick Hirsch David Solo Joseph Reagle Donald Eastlake and Thomas Roessler. XML Signature Syntax and Processing (Second Edition). W3C recommendation W3C June 2008."},{"key":"e_1_3_2_1_15_1","unstructured":"ideascale. ideascale 2014. {online} http:\/\/ideascale.com\/.  ideascale. ideascale 2014. {online} http:\/\/ideascale.com\/."},{"key":"e_1_3_2_1_16_1","unstructured":"Instructure. Canvas 2014. {online} http:\/\/www.instructure.com\/.  Instructure. Canvas 2014. {online} http:\/\/www.instructure.com\/."},{"key":"e_1_3_2_1_17_1","volume-title":"Michael Kay. XSL Transformations (XSLT) Version 2.0","year":"2009"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1103022.1103026"},{"key":"e_1_3_2_1_19_1","volume-title":"MD","author":"Peter","year":"2011"},{"key":"e_1_3_2_1_20_1","unstructured":"Timothy D. Morgan and Omar Al Ibrahim. XML Schema DTD and Entity Attacks - A Compendium of Known Techniques. 2014.  Timothy D. Morgan and Omar Al Ibrahim. XML Schema DTD and Entity Attacks - A Compendium of Known Techniques. 2014."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/11812128_26"},{"key":"e_1_3_2_1_22_1","unstructured":"OneLogin. OneLogin Partners 2014. {online} http:\/\/www.onelogin.com\/partners\/app-partners\/.  OneLogin. OneLogin Partners 2014. {online} http:\/\/www.onelogin.com\/partners\/app-partners\/."},{"key":"e_1_3_2_1_23_1","unstructured":"OWASP Foundation. Cross-Site Request Forgery (CSRF). https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF) 2013. {online} https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF).  OWASP Foundation. Cross-Site Request Forgery (CSRF). https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF) 2013. {online} https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF)."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2003.1250582"},{"key":"e_1_3_2_1_25_1","unstructured":"S. Cantor et al. Assertions and Protocols for the OASIS Security Assertion Markup Language (SAML) V2.0 March 2005.  S. Cantor et al. Assertions and Protocols for the OASIS Security Assertion Markup Language (SAML) V2.0 March 2005."},{"key":"e_1_3_2_1_26_1","unstructured":"S. Cantor et al. Security and Privacy Considerations for the OASIS Security Assertion Markup. Language (SAML) V2.0 March 2005.  S. Cantor et al. Security and Privacy Considerations for the OASIS Security Assertion Markup. Language (SAML) V2.0 March 2005."},{"key":"e_1_3_2_1_27_1","unstructured":"Kalayan Sudia Santosh Bulusu. AStudy on Cloud Computing Security Challenges. Master's thesis School of Computing Blekinge Institute of Technology SE-371 79 Karlskrona Sweden January 2012.  Kalayan Sudia Santosh Bulusu. AStudy on Cloud Computing Security Challenges. Master's thesis School of Computing Blekinge Institute of Technology SE-371 79 Karlskrona Sweden January 2012."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046660.2046664"},{"key":"e_1_3_2_1_29_1","volume-title":"21st USENIX Security Symposium","author":"Somorovsky Juraj","year":"2012"},{"key":"e_1_3_2_1_30_1","unstructured":"C. M. Sperberg-McQueen Henry S. Thompson Murray Maloney Henry S. Thompson David Beech Noah Mendelsohn and Shudi (Sandy) Gao. W3C XML Schema Definition Language (XSD) 1.1 Part 1: Structures. Last call WD W3C December 2009.  C. M. Sperberg-McQueen Henry S. Thompson Murray Maloney Henry S. Thompson David Beech Noah Mendelsohn and Shudi (Sandy) Gao. W3C XML Schema Definition Language (XSD) 1.1 Part 1: Structures. Last call WD W3C December 2009."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382238"},{"key":"e_1_3_2_1_32_1","unstructured":"Talking Cloud. Top 100 Cloud Services Providers (CSPs) List And Research 2014. {online} http:\/\/talkincloud.com\/tc100.  Talking Cloud. Top 100 Cloud Services Providers (CSPs) List And Research 2014. {online} http:\/\/talkincloud.com\/tc100."},{"key":"e_1_3_2_1_33_1","unstructured":"The authors of the paper. Instructure Advisory IAC00722 - SAML Ruby gem vulnerability. https:\/\/help.instructure.com\/entries\/46981014-Instructure-Advisory-IAC00722-SAML-Ruby-gem-vulnerability Feb 2014.  The authors of the paper. Instructure Advisory IAC00722 - SAML Ruby gem vulnerability. https:\/\/help.instructure.com\/entries\/46981014-Instructure-Advisory-IAC00722-SAML-Ruby-gem-vulnerability Feb 2014."},{"key":"e_1_3_2_1_34_1","volume-title":"Multiple CVEs: VU 190556","author":"The","year":"2014"},{"key":"e_1_3_2_1_35_1","unstructured":"The authors of the paper. Responsible Disclosure Policy Contributors. http:\/\/www.zendesk.com\/company\/responsible-disclosurepolicy Feb 2014.  The authors of the paper. Responsible Disclosure Policy Contributors. http:\/\/www.zendesk.com\/company\/responsible-disclosurepolicy Feb 2014."},{"key":"e_1_3_2_1_36_1","unstructured":"The authors of the paper. SAML attacks on Canvas interface. https:\/\/help.instructure.com\/entries\/26920510-Instructure-Advisory-IAC44584-SAML-Signature-Wrapping Feb 2014.  The authors of the paper. SAML attacks on Canvas interface. https:\/\/help.instructure.com\/entries\/26920510-Instructure-Advisory-IAC44584-SAML-Signature-Wrapping Feb 2014."},{"key":"e_1_3_2_1_37_1","unstructured":"The authors of the paper. SAML attacks on Clarizen interface. http:\/\/www.clarizen.com\/security-log.html Feb 2014.  The authors of the paper. SAML attacks on Clarizen interface. http:\/\/www.clarizen.com\/security-log.html Feb 2014."},{"key":"e_1_3_2_1_38_1","unstructured":"TimeOffManager. TimeOffManager 2014.  TimeOffManager. TimeOffManager 2014."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.30"},{"key":"e_1_3_2_1_40_1","unstructured":"Wikipedia. Cloud computing providers 2014. {online} http:\/\/en.wikipedia.org\/wiki\/Category: Cloud_computing_providers.  Wikipedia. Cloud computing providers 2014. {online} http:\/\/en.wikipedia.org\/wiki\/Category: Cloud_computing_providers."},{"key":"e_1_3_2_1_41_1","volume-title":"NDSS","author":"Xing Luyi","year":"2013"},{"key":"e_1_3_2_1_42_1","volume-title":"Evans Yuchen Zhou. Automated Testing of Web Applications for Single Sign-On Vulnerabilities. In 23rd USENIX Security Symposium (USENIX Security 14)","author":"David","year":"2014"},{"key":"e_1_3_2_1_43_1","unstructured":"Zendesk. Zendesk 2014. {online} http:\/\/zendesk.com\/.  Zendesk. Zendesk 2014. {online} http:\/\/zendesk.com\/."},{"key":"e_1_3_2_1_44_1","unstructured":"Zoho. Zoho 2014. {online} http:\/\/www.zoho.com\/.  Zoho. Zoho 2014. {online} http:\/\/www.zoho.com\/."},{"key":"e_1_3_2_1_45_1","first-page":"8","article-title":"The Anatomy of Cross Site Scripting","author":"Zuchlinski Gavin","year":"2003","journal-title":"Hitchhiker's World"}],"event":{"name":"CCS'14: 2014 ACM SIGSAC Conference on Computer and Communications Security","location":"Scottsdale Arizona USA","acronym":"CCS'14","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 6th edition of the ACM Workshop on Cloud Computing Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2664168.2664172","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2664168.2664172","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T06:12:01Z","timestamp":1750227121000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2664168.2664172"}},"subtitle":["Security Analysis of SaaS Single Sign-On Solutions in the Cloud"],"short-title":[],"issued":{"date-parts":[[2014,11,7]]},"references-count":45,"alternative-id":["10.1145\/2664168.2664172","10.1145\/2664168"],"URL":"https:\/\/doi.org\/10.1145\/2664168.2664172","relation":{},"subject":[],"published":{"date-parts":[[2014,11,7]]},"assertion":[{"value":"2014-11-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}