| Paper Abstract and Keywords |
| Presentation |
2023-10-04 17:55
Access Control Method to Prevent ID Token Abuse on OpenID Connect Junki Yuasa, Taisho Sasada, Yuzo Taenaka, Youki Kadobayashi (NAIST) NS2023-81 |
| Abstract |
(in Japanese) |
(See Japanese page) |
| (in English) |
In recent years, there has been a rapid increase in web services that require authentication, leading to the widespread adoption of Single Sign-On (SSO) to simplify user account management. Among these services, those utilizing the OpenID Connect protocol, the most common SSO protocol, often authenticate users through ID Token issued by ID providers. However, there's a risk that attackers can steal these ID Token from legitimate users and engage in impersonation attacks. This research introduces an access control mechanism to address this challenge. This mechanism monitors and verifies requests using ID Token at the Relying Party (RP), ensuring appropriate access control based on the verification results even after authentication. Specifically, it verifies user authenticity through the examination of signatures created using secret keys assigned during user registration, as well as by assessing the validity of the requests and sessions. Through the implementation of our proposed system, we confirmed that proper access control measures are in place even when attackers possess the genuine user's authentication credentials or ID token. |
| Keyword |
(in Japanese) |
(See Japanese page) |
| (in English) |
Access Control / User Authenticity / Single Sign-On / OpenID Connect / ID Token / / / |
| Reference Info. |
IEICE Tech. Rep., vol. 123, no. 198, NS2023-81, pp. 53-58, Oct. 2023. |
| Paper # |
NS2023-81 |
| Date of Issue |
2023-09-27 (NS) |
| ISSN |
Online edition: ISSN 2432-6380 |
Copyright and reproduction |
All rights are reserved and no part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopy, recording, or any information storage and retrieval system, without permission in writing from the publisher. Notwithstanding, instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. (License No.: 10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
| Download PDF |
NS2023-81 |
| Conference Information |
| Committee |
NS |
| Conference Date |
2023-10-04 - 2023-10-06 |
| Place (in Japanese) |
(See Japanese page) |
| Place (in English) |
Hokkaidou University + Online |
| Topics (in Japanese) |
(See Japanese page) |
| Topics (in English) |
Network architecture (5G, Local 5G, Beyond5G, Mobile networks, Ad-hoc and sensor networks, Overlay and P2P networks, Programmable networks, SDN/NFV, IoT, Network slicing), Next generation packet transport (High speed Ethernet, IP over WDM, Multi-service package technology, MPLS), Grid, etc. |
| Paper Information |
| Registration To |
NS |
| Conference Code |
2023-10-NS |
| Language |
Japanese |
| Title (in Japanese) |
(See Japanese page) |
| Sub Title (in Japanese) |
(See Japanese page) |
| Title (in English) |
Access Control Method to Prevent ID Token Abuse on OpenID Connect |
| Sub Title (in English) |
|
| Keyword(1) |
Access Control |
| Keyword(2) |
User Authenticity |
| Keyword(3) |
Single Sign-On |
| Keyword(4) |
OpenID Connect |
| Keyword(5) |
ID Token |
| Keyword(6) |
|
| Keyword(7) |
|
| Keyword(8) |
|
| 1st Author's Name |
Junki Yuasa |
| 1st Author's Affiliation |
Nara Institute of Science and Technology (NAIST) |
| 2nd Author's Name |
Taisho Sasada |
| 2nd Author's Affiliation |
Nara Institute of Science and Technology (NAIST) |
| 3rd Author's Name |
Yuzo Taenaka |
| 3rd Author's Affiliation |
Nara Institute of Science and Technology (NAIST) |
| 4th Author's Name |
Youki Kadobayashi |
| 4th Author's Affiliation |
Nara Institute of Science and Technology (NAIST) |
| 5th Author's Name |
|
| 5th Author's Affiliation |
() |
| 6th Author's Name |
|
| 6th Author's Affiliation |
() |
| 7th Author's Name |
|
| 7th Author's Affiliation |
() |
| 8th Author's Name |
|
| 8th Author's Affiliation |
() |
| 9th Author's Name |
|
| 9th Author's Affiliation |
() |
| 10th Author's Name |
|
| 10th Author's Affiliation |
() |
| 11th Author's Name |
|
| 11th Author's Affiliation |
() |
| 12th Author's Name |
|
| 12th Author's Affiliation |
() |
| 13th Author's Name |
|
| 13th Author's Affiliation |
() |
| 14th Author's Name |
|
| 14th Author's Affiliation |
() |
| 15th Author's Name |
|
| 15th Author's Affiliation |
() |
| 16th Author's Name |
|
| 16th Author's Affiliation |
() |
| 17th Author's Name |
|
| 17th Author's Affiliation |
() |
| 18th Author's Name |
|
| 18th Author's Affiliation |
() |
| 19th Author's Name |
|
| 19th Author's Affiliation |
() |
| 20th Author's Name |
|
| 20th Author's Affiliation |
() |
| 21st Author's Name |
|
| 21st Author's Affiliation |
() |
| 22nd Author's Name |
|
| 22nd Author's Affiliation |
() |
| 23rd Author's Name |
|
| 23rd Author's Affiliation |
() |
| 24th Author's Name |
|
| 24th Author's Affiliation |
() |
| 25th Author's Name |
|
| 25th Author's Affiliation |
() |
| 26th Author's Name |
/ / |
| 26th Author's Affiliation |
()
() |
| 27th Author's Name |
/ / |
| 27th Author's Affiliation |
()
() |
| 28th Author's Name |
/ / |
| 28th Author's Affiliation |
()
() |
| 29th Author's Name |
/ / |
| 29th Author's Affiliation |
()
() |
| 30th Author's Name |
/ / |
| 30th Author's Affiliation |
()
() |
| 31st Author's Name |
/ / |
| 31st Author's Affiliation |
()
() |
| 32nd Author's Name |
/ / |
| 32nd Author's Affiliation |
()
() |
| 33rd Author's Name |
/ / |
| 33rd Author's Affiliation |
()
() |
| 34th Author's Name |
/ / |
| 34th Author's Affiliation |
()
() |
| 35th Author's Name |
/ / |
| 35th Author's Affiliation |
()
() |
| 36th Author's Name |
/ / |
| 36th Author's Affiliation |
()
() |
| Speaker |
Author-1 |
| Date Time |
2023-10-04 17:55:00 |
| Presentation Time |
25 minutes |
| Registration for |
NS |
| Paper # |
NS2023-81 |
| Volume (vol) |
vol.123 |
| Number (no) |
no.198 |
| Page |
pp.53-58 |
| #Pages |
6 |
| Date of Issue |
2023-09-27 (NS) |