Analyzing proposals for improving authentication on the TLS-/SSL-protected Web.

Saved in:
Bibliographic Details
Title: Analyzing proposals for improving authentication on the TLS-/SSL-protected Web.
Authors: Brown, Christopher1 wcbrown@usna.edu, Jenkins, Michael2 mjjenki@tycho.ncsc.mil
Source: International Journal of Information Security. Nov2016, Vol. 15 Issue 6, p621-635. 15p.
Subjects: Internet security, Transport protocols (Computer network protocols), Secure Sockets Layer (Computer network protocol), Computer network protocols, Public key cryptography, Computer access control
Abstract: 'Secure' Web browsing with HTTPS uses TLS/SSL and X.509 certificates to provide authenticated, confidential communication between Web clients and Web servers. The authentication component of the system has a variety of weaknesses, which have led to a variety of proposals for improving the current environment. In this paper, we survey, analyze, compare and contrast five prominent proposals. To do this, we attempt to systematically capture the properties one might require of such a system: authentication properties, forensics/privacy properties, usability properties and pragmatic properties. Enumerating these properties is an important part of understanding these proposals and the nature of the authentication problem for the secure Web. Finally, we offer a few conclusions and suggestions pertaining to these proposals and possible future directions of research. [ABSTRACT FROM AUTHOR]
Copyright of International Journal of Information Security is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Links:
  – Type: pdflink
Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 118832930
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Analyzing proposals for improving authentication on the TLS-/SSL-protected Web.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Brown%2C+Christopher%22">Brown, Christopher</searchLink><relatesTo>1</relatesTo><i> wcbrown@usna.edu</i><br /><searchLink fieldCode="AR" term="%22Jenkins%2C+Michael%22">Jenkins, Michael</searchLink><relatesTo>2</relatesTo><i> mjjenki@tycho.ncsc.mil</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22International+Journal+of+Information+Security%22">International Journal of Information Security</searchLink>. Nov2016, Vol. 15 Issue 6, p621-635. 15p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Internet+security%22">Internet security</searchLink><br /><searchLink fieldCode="DE" term="%22Transport+protocols+%28Computer+network+protocols%29%22">Transport protocols (Computer network protocols)</searchLink><br /><searchLink fieldCode="DE" term="%22Secure+Sockets+Layer+%28Computer+network+protocol%29%22">Secure Sockets Layer (Computer network protocol)</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+network+protocols%22">Computer network protocols</searchLink><br /><searchLink fieldCode="DE" term="%22Public+key+cryptography%22">Public key cryptography</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+access+control%22">Computer access control</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: 'Secure' Web browsing with HTTPS uses TLS/SSL and X.509 certificates to provide authenticated, confidential communication between Web clients and Web servers. The authentication component of the system has a variety of weaknesses, which have led to a variety of proposals for improving the current environment. In this paper, we survey, analyze, compare and contrast five prominent proposals. To do this, we attempt to systematically capture the properties one might require of such a system: authentication properties, forensics/privacy properties, usability properties and pragmatic properties. Enumerating these properties is an important part of understanding these proposals and the nature of the authentication problem for the secure Web. Finally, we offer a few conclusions and suggestions pertaining to these proposals and possible future directions of research. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of International Journal of Information Security is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=118832930
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1007/s10207-016-0316-2
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 15
        StartPage: 621
    Subjects:
      – SubjectFull: Internet security
        Type: general
      – SubjectFull: Transport protocols (Computer network protocols)
        Type: general
      – SubjectFull: Secure Sockets Layer (Computer network protocol)
        Type: general
      – SubjectFull: Computer network protocols
        Type: general
      – SubjectFull: Public key cryptography
        Type: general
      – SubjectFull: Computer access control
        Type: general
    Titles:
      – TitleFull: Analyzing proposals for improving authentication on the TLS-/SSL-protected Web.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Brown, Christopher
      – PersonEntity:
          Name:
            NameFull: Jenkins, Michael
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 11
              Text: Nov2016
              Type: published
              Y: 2016
          Identifiers:
            – Type: issn-print
              Value: 16155262
          Numbering:
            – Type: volume
              Value: 15
            – Type: issue
              Value: 6
          Titles:
            – TitleFull: International Journal of Information Security
              Type: main
ResultId 1