Skip to main navigation Skip to search Skip to main content

Formal analysis of information card federated identity-management protocol

  • Juan Wang
  • , Hongxin Hu
  • , Bo Zhao
  • , Fei Yan
  • , Huanguo Zhang
  • , Qianhong Wu
  • Wuhan University
  • Ministry of Education of the People's Republic of China

Research output: Contribution to journalArticlepeer-review

4 Scopus citations

Abstract

Information Card (InfoCard) is a user-centric identity management metasystem. It has been accepted as a standard of OASIS Identity Metasystem Interoperability Technical Committee. However, there is currently a lack of security analysis to InfoCard protocol, especially, with formal methods. In this paper, we accommodate such a requirement by analyzing security properties of InfoCard protocol adopting a formal protocol analysis tool. Our analysis result discovers that current InfoCard protocol is vulnerable against the session replay attack. Furthermore, we reveal the importance of two optional elements in InfoCard metasystem, token scope and proof key, and found that InfoCard protocol will be susceptible to manin-the-middle attack and token replay attack if these two optional elements lack.

Original languageEnglish
Pages (from-to)83-88
Number of pages6
JournalChinese Journal of Electronics
Volume22
Issue number1
StatePublished - Jan 2013

Keywords

  • Automated validation of internet security protocols and applications (AVISPA)
  • Identity
  • Information Card
  • User-centric

Fingerprint

Dive into the research topics of 'Formal analysis of information card federated identity-management protocol'. Together they form a unique fingerprint.

Cite this