Hardening SAML by Integrating SSO and Multi-Factor Authentication (MFA) in the Cloud

被引:4
|
作者
Karie, Nickson M. [1 ]
Kebande, Victor R. [2 ]
Ikuesan, Richard A. [3 ]
Sookhak, Mehdi [4 ]
Venter, H. S. [5 ]
机构
[1] Edith Cowan Univ, Dept Comp Sci, Joondalup, Australia
[2] Malmo Univ, Dept Comp Sci, Nordenskioldsgatan, Malmo, Sweden
[3] Qatar Community Coll, Dept Comp Sci, Doha, Qatar
[4] Illinois State Univ, Sch Informat Technol, Normal, IL 61761 USA
[5] Univ Pretoria, Dept Comp Sci, Pretoria, South Africa
来源
3RD INTERNATIONAL CONFERENCE ON NETWORKING, INFORMATION SYSTEM & SECURITY (NISS'20) | 2020年
关键词
SAML; Single sign on; Multi-Factor Authentication; CVSS; SINGLE SIGN-ON;
D O I
10.1145/3386723.3387875
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Even though the cloud paradigm and its associated services has been adopted in various enterprise applications, there has been major issues with regard to authenticating users' critical data. Single Sign on (SSO) is a user authentication technique through which a server authenticates and allows a user to use a single aspect of login credentials, for example, to access multiple services in the cloud. Even though SSO reduces the number of logins that are needed over heterogeneous environments, the risk that might be associated with the security of SSO might be detrimental if, for example, a Man-in-the Middle (MITM) attacker manages to gain control of the SSO credentials. It is also possible to get the identity of the users who have logged into Active Directory or intranet and this identity can easily be used to log into other web-based applications, and this requires the use of the Security Assertion Mark-up Language (SAML). SAML is basically a standard that allows users to be logged into applications as per their sessions. The problem that this paper addresses is the lack of a proactive technique of hardening cloud-based SAML while combining SSO with a Multi-Factor Authentication (MFA) at the time of writing this paper. The authors have, therefore, proposed an effective approach that unifies SSO with MFA in this context. Based on the base score index conducted over Common Vulnerability Scoring System (CVSS), the architecture proves to be reliable, feasible and with better performance.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Multi-Factor Authentication on Cloud
    Khan, Salman H.
    Akbar, M. Ali
    2015 INTERNATIONAL CONFERENCE ON DIGITAL IMAGE COMPUTING: TECHNIQUES AND APPLICATIONS (DICTA), 2015, : 548 - 554
  • [2] Multi-factor Authentication based on Multimodal Biometrics (MFA-MB) for Cloud Computing
    Mansour, Abdeljebar
    Sadik, Mohamed
    Sabir, Essaid
    2015 IEEE/ACS 12TH INTERNATIONAL CONFERENCE OF COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2015,
  • [3] Enhanced Multi-factor Authentication on the Cloud
    Alyounis, Essa
    Dinah, Quanq
    INNOVATION MANAGEMENT AND SUSTAINABLE ECONOMIC COMPETITIVE ADVANTAGE: FROM REGIONAL DEVELOPMENT TO GLOBAL GROWTH, VOLS I - VI, 2015, 2015, : 69 - 77
  • [4] Implementing multi-factor authentication (MFA) for robust network access security
    De, Indrajit
    Agarwal, Ambuj Kumar
    Bhushan, Bharat
    Kalnawat, Aarti
    Mathurkar, Piyush
    Garg, Amit
    JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2024, 27 (2B): : 821 - 832
  • [5] CLOUD STORAGE SECURITY USING MULTI-FACTOR AUTHENTICATION
    Nikam, Rushikesh
    Potey, Manish
    2016 INTERNATIONAL CONFERENCE ON RECENT ADVANCES AND INNOVATIONS IN ENGINEERING (ICRAIE), 2016,
  • [6] A Systematic Survey of Multi-Factor Authentication for Cloud Infrastructure
    Otta, Soumya Prakash
    Panda, Subhrakanta
    Gupta, Maanak
    Hota, Chittaranjan
    FUTURE INTERNET, 2023, 15 (04):
  • [7] Multi-Factor Authentication for Secured Financial Transactions in Cloud Environment
    Prabakaran, D.
    Ramachandran, Shyamala
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 70 (01): : 1781 - 1798
  • [8] Strengthening Cloud Security: An Innovative Multi-Factor Multi-Layer Authentication Framework for Cloud User Authentication
    Mostafa, Ayman Mohamed
    Ezz, Mohamed
    Elbashir, Murtada K.
    Alruily, Meshrif
    Hamouda, Eslam
    Alsarhani, Mohamed
    Said, Wael
    APPLIED SCIENCES-BASEL, 2023, 13 (19):
  • [9] Multi-observed Multi-factor Authentication: A Multi-factor Authentication Using Single Credential
    Nozaki, Shinnosuke
    Serizawa, Ayumi
    Yoshihira, Mizuho
    Fujita, Masahiro
    Shibata, Yoichi
    Yamanaka, Tadakazu
    Matsuda, Nori
    Ohki, Tetsushi
    Nishigaki, Masakatsu
    ADVANCES IN NETWORK-BASED INFORMATION SYSTEMS, NBIS-2022, 2022, 526 : 201 - 211
  • [10] To Discovery The Cloud Services Authentication An Expert Based System Using Multi-Factor Authentication
    Kumar, G. Senthil
    Kandavel, N.
    Madhavan, K.
    2020 6TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING AND COMMUNICATION SYSTEMS (ICACCS), 2020, : 1014 - 1016