loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
The Third Advanced International Conference on Telecommunications (AICT'07)
Towards Security Analyses of an Identity Federation Protocol for Web Services in Convergent Networks
Morne, Mauritius
May 13-May 19
ISBN: 0-7695-2843-0
Maurice ter Beek, ISTI-CNR, Italy
Corrado Moiso, Telecom Italia, Italy
Marinella Petrocchi, IIT-CNR, Italy
We describe a formal approach to the analysis of security aspects of an identity federation protocol for web services in convergent networks. This network protocol was proposed by Telecom Italia as a solution to allow end users to access services on the web through different access networks without explicitly providing any credentials, while the service providers can trust the user?s identity information provided by the access networks and access some user data. As a first step towards a full-blown formal security analysis of the protocol, we specify three user scenarios in the process algebra Crypto-CCS and verify the vulnerability of one of these specifications w.r.t. a man-in-the-middle attack with the model checker PaMoChSA.
Citation:
Maurice ter Beek, Corrado Moiso, Marinella Petrocchi, "Towards Security Analyses of an Identity Federation Protocol for Web Services in Convergent Networks," aict, pp.31, The Third Advanced International Conference on Telecommunications (AICT'07), 2007
Usage of this product signifies your acceptance of the Terms of Use.