Web security: Authentication protocols and their analysis

Citation
W. Wen et F. Mizoguchi, Web security: Authentication protocols and their analysis, NEW GEN COM, 19(3), 2001, pp. 283-299
Citations number
29
Categorie Soggetti
Computer Science & Engineering
Journal title
NEW GENERATION COMPUTING
ISSN journal
02883635 → ACNP
Volume
19
Issue
3
Year of publication
2001
Pages
283 - 299
Database
ISI
SICI code
0288-3635(2001)19:3<283:WSAPAT>2.0.ZU;2-L
Abstract
Authentication is one of the basic building blocks of computer security. It is achieved through the execution of an authentication protocol between tw o or more parties. One such protocol, the Secure Socket Layer (SSL) protoco l, has become the de facto standard for Web security. This paper provides a n overview of results and methods used in analyzing authentication protocol s. The aim is to provide a bird's eye view of the assumptions, methods, and results that are available for anyone who is interested in designing new s ecurity protocols or applying a new analysis approach. A detailed descripti on of the SSL handshake protocol as well as how changes in environment assu mption can lead to unexpected consequences, is provided. A fix to the weakn ess is also described.