Analyzing proposals for improving authentication on the TLS-/SSL-protected Web.
Saved in:
| Title: | Analyzing proposals for improving authentication on the TLS-/SSL-protected Web. |
|---|---|
| Authors: | Brown, Christopher1 wcbrown@usna.edu, Jenkins, Michael2 mjjenki@tycho.ncsc.mil |
| Source: | International Journal of Information Security. Nov2016, Vol. 15 Issue 6, p621-635. 15p. |
| Subjects: | Internet security, Transport protocols (Computer network protocols), Secure Sockets Layer (Computer network protocol), Computer network protocols, Public key cryptography, Computer access control |
| Abstract: | 'Secure' Web browsing with HTTPS uses TLS/SSL and X.509 certificates to provide authenticated, confidential communication between Web clients and Web servers. The authentication component of the system has a variety of weaknesses, which have led to a variety of proposals for improving the current environment. In this paper, we survey, analyze, compare and contrast five prominent proposals. To do this, we attempt to systematically capture the properties one might require of such a system: authentication properties, forensics/privacy properties, usability properties and pragmatic properties. Enumerating these properties is an important part of understanding these proposals and the nature of the authentication problem for the secure Web. Finally, we offer a few conclusions and suggestions pertaining to these proposals and possible future directions of research. [ABSTRACT FROM AUTHOR] |
| Copyright of International Journal of Information Security is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Database: | Engineering Source |
| FullText | Links: – Type: pdflink Text: Availability: 0 |
|---|---|
| Header | DbId: egs DbLabel: Engineering Source An: 118832930 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 0 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: Analyzing proposals for improving authentication on the TLS-/SSL-protected Web. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Brown%2C+Christopher%22">Brown, Christopher</searchLink><relatesTo>1</relatesTo><i> wcbrown@usna.edu</i><br /><searchLink fieldCode="AR" term="%22Jenkins%2C+Michael%22">Jenkins, Michael</searchLink><relatesTo>2</relatesTo><i> mjjenki@tycho.ncsc.mil</i> – Name: TitleSource Label: Source Group: Src Data: <searchLink fieldCode="JN" term="%22International+Journal+of+Information+Security%22">International Journal of Information Security</searchLink>. Nov2016, Vol. 15 Issue 6, p621-635. 15p. – Name: Subject Label: Subjects Group: Su Data: <searchLink fieldCode="DE" term="%22Internet+security%22">Internet security</searchLink><br /><searchLink fieldCode="DE" term="%22Transport+protocols+%28Computer+network+protocols%29%22">Transport protocols (Computer network protocols)</searchLink><br /><searchLink fieldCode="DE" term="%22Secure+Sockets+Layer+%28Computer+network+protocol%29%22">Secure Sockets Layer (Computer network protocol)</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+network+protocols%22">Computer network protocols</searchLink><br /><searchLink fieldCode="DE" term="%22Public+key+cryptography%22">Public key cryptography</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+access+control%22">Computer access control</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: 'Secure' Web browsing with HTTPS uses TLS/SSL and X.509 certificates to provide authenticated, confidential communication between Web clients and Web servers. The authentication component of the system has a variety of weaknesses, which have led to a variety of proposals for improving the current environment. In this paper, we survey, analyze, compare and contrast five prominent proposals. To do this, we attempt to systematically capture the properties one might require of such a system: authentication properties, forensics/privacy properties, usability properties and pragmatic properties. Enumerating these properties is an important part of understanding these proposals and the nature of the authentication problem for the secure Web. Finally, we offer a few conclusions and suggestions pertaining to these proposals and possible future directions of research. [ABSTRACT FROM AUTHOR] – Name: AbstractSuppliedCopyright Label: Group: Ab Data: <i>Copyright of International Journal of Information Security is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=118832930 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.1007/s10207-016-0316-2 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 15 StartPage: 621 Subjects: – SubjectFull: Internet security Type: general – SubjectFull: Transport protocols (Computer network protocols) Type: general – SubjectFull: Secure Sockets Layer (Computer network protocol) Type: general – SubjectFull: Computer network protocols Type: general – SubjectFull: Public key cryptography Type: general – SubjectFull: Computer access control Type: general Titles: – TitleFull: Analyzing proposals for improving authentication on the TLS-/SSL-protected Web. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Brown, Christopher – PersonEntity: Name: NameFull: Jenkins, Michael IsPartOfRelationships: – BibEntity: Dates: – D: 01 M: 11 Text: Nov2016 Type: published Y: 2016 Identifiers: – Type: issn-print Value: 16155262 Numbering: – Type: volume Value: 15 – Type: issue Value: 6 Titles: – TitleFull: International Journal of Information Security Type: main |
| ResultId | 1 |