{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:44:52Z","timestamp":1781106292882,"version":"3.54.1"},"reference-count":31,"publisher":"IGI Global Scientific Publishing","issue":"4","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011,10,1]]},"abstract":"<p>In recent research, two approaches to protect SAML based Federated Identity Management (FIM) against man-in-the-middle attacks have been proposed. One approach is to bind the SAML assertion and the SAML artifact to the public key contained in a TLS client certificate. Another approach is to strengthen the Same Origin Policy of the browser by taking into account the security guarantees TLS gives. This work presents a third approach which is of further interest beyond IDM protocols, especially for mobile devices relying heavily on the security offered by web technologies. By binding the SAML assertion to cryptographically derived values of the TLS session that has been agreed upon between client and the service provider, this approach provides anonymity of the (mobile) browser while allowing Relying Party and Identity Provider to detect the presence of a man-in-the-middle attack.<\/p>","DOI":"10.4018\/jmcmc.2011100102","type":"journal-article","created":{"date-parts":[[2011,10,19]],"date-time":"2011-10-19T12:40:36Z","timestamp":1319028036000},"page":"20-35","source":"Crossref","is-referenced-by-count":0,"title":["On Cryptographically Strong Bindings of SAML Assertions to Transport Layer Security"],"prefix":"10.4018","volume":"3","author":[{"given":"Florian","family":"Kohlar","sequence":"first","affiliation":[{"name":"Ruhr University Bochum, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"J\u00f6rg","family":"Schwenk","sequence":"additional","affiliation":[{"name":"Ruhr University Bochum, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Meiko","family":"Jensen","sequence":"additional","affiliation":[{"name":"Ruhr University Bochum, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sebastian","family":"Gajek","sequence":"additional","affiliation":[{"name":"Tel Aviv University, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jmcmc.2011100102-0","doi-asserted-by":"crossref","unstructured":"Backes, M., Cervesato, I., Jaggard, A. D., Scedrov, A., & Tsay, J.-K. (2006). Cryptographically sound security proofs for basic and public-key kerberos. Retrieved from http:\/\/faculty.nps.edu\/gwdinolt\/ProtocolExchange\/Fall2006\/ProtocoleXchange092806_CompProofsKerberos.pdf","DOI":"10.1007\/11863908_23"},{"key":"jmcmc.2011100102-1","doi-asserted-by":"crossref","unstructured":"Boldyreva, A., & Kumar, V. (2007). Provable-security analysis of authenticated encryption in kerberos. Retrieved from http:\/\/www.cc.gatech.edu\/~virendra\/papers\/BK07.pdf","DOI":"10.1109\/SP.2007.19"},{"key":"jmcmc.2011100102-2","unstructured":"Cantor, S., Hirsch, F., Kemp, J., Philpott, R., & Maler, E. (2005). Bindings for the OASIS security assertion markup language (SAML) v2.0. Retrieved from http:\/\/docs.oasis-open.org\/security\/saml\/v2.0\/saml-bindings-2.0-os.pdf"},{"key":"jmcmc.2011100102-3","unstructured":"Cantor, S., Kemp, J., Philpott, R., & Maler, E. (2005a). Assertions and protocol for the OASIS security assertion markup language (SAML) v2.0. Retrieved from http:\/\/docs.oasis-open.org\/security\/saml\/v2.0\/saml-core-2.0-os.pdf"},{"key":"jmcmc.2011100102-4","unstructured":"Cantor, S., Kemp, J., Philpott, R., & Maler, E. (2005b). Profiles for the OASIS security assertion markup language (SAML) v2.0. Retrieved from http:\/\/docs.oasis-open.org\/security\/saml\/v2.0\/saml-profiles-2.0-os.pdf"},{"key":"jmcmc.2011100102-5","doi-asserted-by":"crossref","unstructured":"Dhamija, R., Tygar, J. D., & Hearst, M. A. (2006). Why phishing works. In Proceedings of the SIGCHI Conference on Human Factors in Computing Systems (pp. 581-590).","DOI":"10.1145\/1124772.1124861"},{"key":"jmcmc.2011100102-6","doi-asserted-by":"crossref","unstructured":"Dierks, T., & Allen, C. (1999). RFC 2246: The TLS protocol version, 1.0.[REMOVED HYPERLINK FIELD] Retrieved from http:\/\/www.ietf.org\/rfc\/rfc2246.txt","DOI":"10.17487\/rfc2246"},{"key":"jmcmc.2011100102-7","doi-asserted-by":"crossref","unstructured":"Dierks, T., & Rescorla, E. (2006). RFC 4346: The transport layer security (TLS) protocol, version 1.1. Retrieved from http:\/\/www.ietf.org\/mail-archive\/web\/ietf-announce\/current\/msg02442.html","DOI":"10.17487\/rfc4346"},{"key":"jmcmc.2011100102-8","doi-asserted-by":"crossref","unstructured":"Dierks, T., & Rescorla, E. (2008). RFC 5246: The transport layer security (TLS) protocol, version 1.2. Retrieved from http:\/\/tools.ietf.org\/html\/rfc5246","DOI":"10.17487\/rfc5246"},{"key":"jmcmc.2011100102-9","author":"S.Gajek","year":"2008","journal-title":"Foundations of provable browser-based security protocols"},{"key":"jmcmc.2011100102-10","doi-asserted-by":"crossref","unstructured":"Gajek, S., Jager, T., Manulis, M., & Schwenk, J. (2008). A browser-based kerberos authentication scheme. In Proceedings of the 13th European Symposium on Research in Computer Security (pp. 115-129).","DOI":"10.1007\/978-3-540-88313-5_8"},{"key":"jmcmc.2011100102-11","doi-asserted-by":"crossref","unstructured":"Gajek, S., Liao, L., & Schwenk, J. (2008). Stronger tls bindings for SAML assertions and SAML artifacts. In Proceedings of the ACM Workshop on Secure Web Services (pp. 11-20).","DOI":"10.1145\/1456492.1456495"},{"key":"jmcmc.2011100102-12","author":"S.Gajek","year":"2008","journal-title":"On the insecurity of Microsoft\u2019s identity metasystem cardspace (Tech. Rep. No. HGI TR-2008-004)"},{"key":"jmcmc.2011100102-13","unstructured":"Gro\u00df, T. (2003). Security analysis of the SAML single sign-on browser\/artifact profile. In Proceedings of the 19th Annual Computer Security Applications Conference (p. 298)."},{"key":"jmcmc.2011100102-14","author":"T.Gro\u00df","year":"2006","journal-title":"SAML artifact information flow revisited.Saml artifact information flow revisited (Research report RZ 3643 99653)"},{"key":"jmcmc.2011100102-15","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2008.09.007"},{"key":"jmcmc.2011100102-16","doi-asserted-by":"crossref","unstructured":"Holz, T., Engelberth, M., & Freiling, F. C. (2009). Learning more about the underground economy: A case-study of keyloggers and dropzones. In Proceedings of the 14th European Symposium on Research in Computer Security (pp. 1-18).","DOI":"10.1007\/978-3-642-04444-1_1"},{"key":"jmcmc.2011100102-17","doi-asserted-by":"crossref","unstructured":"Jensen, M., Gruschka, N., & Herkenh\u00f6ner, R. (2009). A survey of attacks on web services. Computer Science - Research + Development, 24(4), 185-197.","DOI":"10.1007\/s00450-009-0092-6"},{"key":"jmcmc.2011100102-18","unstructured":"Kaminski, D. (2008). Black ops 2008: It\u2019s the end of the cache as we know it: DNS server+client cache poisoning, issues with SSL, breaking *forgot my password* systems, attacking autoupdaters and unhardened parsers, rerouting internal traffic. Retrieved from http:\/\/www.blackhat.com\/presentations\/bh-jp-08\/bh-jp-08-Kaminsky\/BlackHat-Japan-08-Kaminsky-DNS08-BlackOps.pdf[REMOVED HYPERLINK FIELD]"},{"key":"jmcmc.2011100102-19","unstructured":"Kemp, J., Cantor, S., Mishra, P., Philpott, R., & Maler, E. (2005). Authentication context for the OASIS security assertion markup language (SAML) v2.0. Retrieved from http:\/\/docs.oasis-open.org\/security\/saml\/v2.0\/saml-authn-context-2.0-os.pdf"},{"key":"jmcmc.2011100102-20","unstructured":"Klingenstein, N. (2009). SAML v2.0 holder-of-key web browser SSO profile. Retrieved from http:\/\/docs.oasis-open.org\/security\/saml\/Post2.0\/sstc-saml-holder-of-key-browser-sso.pdf"},{"key":"jmcmc.2011100102-21","doi-asserted-by":"crossref","unstructured":"Kormann, D., & Rubin, A. (2000). Risks of the passport single signon protocol. Computer Networks, 33(1-6), 51-58.","DOI":"10.1016\/S1389-1286(00)00048-7"},{"key":"jmcmc.2011100102-22","unstructured":"Microsoft. (n. d.). Passport. Retrieved from https:\/\/accountservices.passport.net\/ppnetworkhome.srf?vv=1000&mkt=EN-US&lc=1033"},{"key":"jmcmc.2011100102-23","unstructured":"MIT. (2011). Kerberos: The network authentication protocol. Retrieved from http:\/\/web.mit.edu\/Kerberos\/"},{"key":"jmcmc.2011100102-24","unstructured":"OASIS. (2008). Security services (SAML) TC. Retrieved from http:\/\/www.oasis-open.org\/committees\/tc_home.php?wg_abbrev=security"},{"key":"jmcmc.2011100102-25","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2003.1250582"},{"key":"jmcmc.2011100102-26","unstructured":"Radack, S. (2003). Electronic authentication: Guidance for selecting secure techniques. Retrieved from http:\/\/www.itl.nist.gov\/lab\/bulletns\/bltnaug04.htm"},{"key":"jmcmc.2011100102-27","doi-asserted-by":"crossref","unstructured":"Schechter, S., Dhamija, R., Ozment, A., & Fischer, I. (2007). The emperor\u2019s new security indicators. In Proceedings of the IEEE Symposium on Security and Privacy (pp. 51-65).","DOI":"10.1109\/SP.2007.35"},{"key":"jmcmc.2011100102-28","unstructured":"Slemko, M. (2001). Microsoft passport to trouble. Retrieved from http:\/\/www.znep.com\/~marcs\/passport\/"},{"key":"jmcmc.2011100102-29","unstructured":"Soghoian, C., & Jakobsson, M. (2007). A deceit-augmented man in the middle attack against Bank of America\u2019s sitekey service. Retrieved from http:\/\/paranoia.dubfire.net\/2007\/04\/deceit-augmented-man-in-middle-attack.html"},{"key":"jmcmc.2011100102-30","unstructured":"Stamm, S., Ramzan, Z., & Jakobsson, M. (2006). Drive-by pharming (Tech. Rep. No. 641). Blommington, IN: Indiana University."}],"container-title":["International Journal of Mobile Computing and Multimedia Communications"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=58903","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,6,10]],"date-time":"2023-06-10T11:58:57Z","timestamp":1686398337000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jmcmc.2011100102"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2011,10,1]]},"references-count":31,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2011,10]]}},"URL":"https:\/\/doi.org\/10.4018\/jmcmc.2011100102","relation":{},"ISSN":["1937-9412","1937-9404"],"issn-type":[{"value":"1937-9412","type":"print"},{"value":"1937-9404","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,10,1]]}}}