Comprehensive Security Analysis of Federated Identity Management
Abstract
Abstract
Analyzing the security of FIdM is a challenging task, on one hand due to the various modes and options that the protocols provide, and on the other hand due to the inherent complexity of the web. A thorough understanding of the security vulnerabilities is required to remodel a stable and secure authentication system. In this paper the challenges and requirements of securing the exchange of information between enterprises have been reported. The goal of this work is to provide an in-depth security analysis of FIdM protocols. The major FIdM protocols SAML, OpenID and OAuth have been discussed. A narrative of the major security attacks and flaws in existing Federated Identity Management have been presented. The paper explores solutions to resolve the security issues reported in existing FIdM and defines a number of possible countermeasures.
Keywords: Federated Identity Management, SAML, OAuth, OpenID, Server Side Request Forgery, Denial-of-Service, Phishing attacks
Cite this Article
Gargi Amoli, Manish Kala,Jitendra Chaurasia. A Comprehensive Security Analysis of Federated Identity Management. Journal of Communication Engineering & Systems. 2017; 7(1): 11–16p.
Downloads
Published
Issue
Section
License
Declaration and Copyright Transfer Form
(to be completed by authors)
I/ We, the undersigned author(s) of the submitted manuscript, hereby declare, that the above manuscript which is submitted for publication in the STM Journals(s), is not published already in part or whole (except in the form of abstract) in any journal or magazine for private or public circulation, and, is not under consideration of publication elsewhere.
- I/We will not withdraw the manuscript after 1 week of submission as I have read the Author Guidelines and will adhere to the guidelines.
- I/We Author(s ) have niether given nor will give this manuscript elsewhere for publishing after submitting in STM Journal(s).
- I/ We have read the original version of the manuscript and am/ are responsible for the thought contents embodied in it. The work dealt in the manuscript is my/ our own, and my/ our individual contribution to this work is significant enough to qualify for authorship.
- I/We also agree to the authorship of the article in the following order:
Author’s name
1. ________________
2. ________________
3. ________________
4. ________________
| We Author(s) tick this box and would request you to consider it as our signature as we agree to the terms of this Copyright Notice, which will apply to this submission if and when it is published by this journal. |