2012 Tenth Annual International Conference on Privacy, Security and Trust 2012
DOI: 10.1109/pst.2012.6297941
|View full text |Cite
|
Sign up to set email alerts
|

Service provider authentication assurance

Abstract: Abstract-The concept of authentication assurance traditionally refers to the robustness of methods and mechanisms for user authentication, including the robustness of initial registration and provisioning of user credentials, as well as the robustness of mechanisms that enforce user authentication during operation. However, the user is not the only party that needs to be authenticated to ensure security of online transactions. In fact, online service provision always involves two parties, typically the user on… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
13
0

Year Published

2013
2013
2021
2021

Publication Types

Select...
4
2
1

Relationship

1
6

Authors

Journals

citations
Cited by 9 publications
(13 citation statements)
references
References 15 publications
0
13
0
Order By: Relevance
“…It would be interesting to apply the prototype methodology that we develop below to their ideal browser. Jøsang et al [16] point out that TLS does not provide semantic server authentication, and can be easily exploited by semantic attacks. However, web browsers can only do syntactic server authentication, while complex user models are needed to deal with semantic attacks.…”
Section: Related Workmentioning
confidence: 99%
“…It would be interesting to apply the prototype methodology that we develop below to their ideal browser. Jøsang et al [16] point out that TLS does not provide semantic server authentication, and can be easily exploited by semantic attacks. However, web browsers can only do syntactic server authentication, while complex user models are needed to deal with semantic attacks.…”
Section: Related Workmentioning
confidence: 99%
“…However, our solutions could also support AAL 4 by implementing support for user certificates in the OffPAD. It can be mentioned that there are currently no frameworks for server authentication assurance levels, although it has been proposed [20,49].…”
Section: Discussionmentioning
confidence: 99%
“…This is a serious vulnerability which is also the reason why phishing attacks often succeed even when TLS is being used for server authentication [20].…”
Section: Server Authentication Supported By the Offpadmentioning
confidence: 99%
See 1 more Smart Citation
“…Instead, server authentication assurance should also be considered. Of course, as typically adopted by the standards for network security such as X.800 (Security Architecture for Open Systems Interconnection), the following two types of authentication should be considered [22]:…”
Section: Presentation Tiermentioning
confidence: 99%