Published: Jun 16, 2016
The following paper has been accepted at the 13th International Conference on Security and Cryptography (SECRYPT 2016):
- Title: Security of Mobile Single Sign-On: a Rational Reconstruction of Facebook Login Solution
- Author: Giada Sciarretta, Alessandro Armando, Roberto Carbone, Silvio Ranise
- Abstract: While there exist many secure authentication and authorization solutions for web applications, their adaptation in the mobile context is a new and open challenge. In this paper, we argue that the lack of a proper reference model for Single Sign-On (SSO) for mobile native applications drives many social network vendors (acting as Identity Providers) to develop their own mobile solution. However, as the implementation details are not well documented, it is difficult to establish the proper security level of these solutions. We thus provide a rational reconstruction of the Facebook SSO flow, including a comparison with the OAuth 2.0 standard and a security analysis obtained testing the Facebook SSO reconstruction against a set of identified SSO attacks. Based on this analysis, we have modified and generalized the Facebook solution proposing a native SSO solution capable of solving the identified vulnerabilities and accommodating any Identity Provider.
- DOI: 10.5220/0005969001470158
About the conference
- Name: 13th International Conference on Security and Cryptography (SECRYPT 2016)
- Date: from July 26, 2016 to July 28, 2016
- Location: Lisbon, Portugal
- Website: http://www.secrypt.org/?y=2016