Analyzing proposals for improving authentication on the TLS-/SSL-protected Web.

Saved in:
Bibliographic Details
Title: Analyzing proposals for improving authentication on the TLS-/SSL-protected Web.
Authors: Brown, Christopher1 wcbrown@usna.edu, Jenkins, Michael2 mjjenki@tycho.ncsc.mil
Source: International Journal of Information Security. Nov2016, Vol. 15 Issue 6, p621-635. 15p.
Subjects: Internet security, Transport protocols (Computer network protocols), Secure Sockets Layer (Computer network protocol), Computer network protocols, Public key cryptography, Computer access control
Abstract: 'Secure' Web browsing with HTTPS uses TLS/SSL and X.509 certificates to provide authenticated, confidential communication between Web clients and Web servers. The authentication component of the system has a variety of weaknesses, which have led to a variety of proposals for improving the current environment. In this paper, we survey, analyze, compare and contrast five prominent proposals. To do this, we attempt to systematically capture the properties one might require of such a system: authentication properties, forensics/privacy properties, usability properties and pragmatic properties. Enumerating these properties is an important part of understanding these proposals and the nature of the authentication problem for the secure Web. Finally, we offer a few conclusions and suggestions pertaining to these proposals and possible future directions of research. [ABSTRACT FROM AUTHOR]
Copyright of International Journal of Information Security is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
Description
Abstract:'Secure' Web browsing with HTTPS uses TLS/SSL and X.509 certificates to provide authenticated, confidential communication between Web clients and Web servers. The authentication component of the system has a variety of weaknesses, which have led to a variety of proposals for improving the current environment. In this paper, we survey, analyze, compare and contrast five prominent proposals. To do this, we attempt to systematically capture the properties one might require of such a system: authentication properties, forensics/privacy properties, usability properties and pragmatic properties. Enumerating these properties is an important part of understanding these proposals and the nature of the authentication problem for the secure Web. Finally, we offer a few conclusions and suggestions pertaining to these proposals and possible future directions of research. [ABSTRACT FROM AUTHOR]
ISSN:16155262
DOI:10.1007/s10207-016-0316-2