Abstract
Information Card (InfoCard) is a user-centric identity management metasystem. It has been accepted as a standard of OASIS Identity Metasystem Interoperability Technical Committee. However, there is currently a lack of security analysis to InfoCard protocol, especially, with formal methods. In this paper, we accommodate such a requirement by analyzing security properties of InfoCard protocol adopting a formal protocol analysis tool. Our analysis result discovers that current InfoCard protocol is vulnerable against the session replay attack. Furthermore, we reveal the importance of two optional elements in InfoCard metasystem, token scope and proof key, and found that InfoCard protocol will be susceptible to manin-the-middle attack and token replay attack if these two optional elements lack.
| Original language | English |
|---|---|
| Pages (from-to) | 83-88 |
| Number of pages | 6 |
| Journal | Chinese Journal of Electronics |
| Volume | 22 |
| Issue number | 1 |
| State | Published - Jan 2013 |
Keywords
- Automated validation of internet security protocols and applications (AVISPA)
- Identity
- Information Card
- User-centric
Fingerprint
Dive into the research topics of 'Formal analysis of information card federated identity-management protocol'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver