Stronger TLS bindings for SAML assertions and SAML artifacts

  • Authors:
  • Sebastian Gajek;Lijun Liao;Jörg Schwenk

  • Affiliations:
  • Ruhr-University Bochum, Bochum, Germany;Ruhr-University Bochum, Bochum, Germany;Ruhr-University Bochum, Bochum, Germany

  • Venue:
  • Proceedings of the 2008 ACM workshop on Secure web services
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Based on recently proposed attack scenarios, we show that SAML assertions and SAML artifacts are still vulnerable to real-world attacks on browser-based implementations. We propose two different bindings of SAML assertions and SAML artifacts to the TLS security layer and show that these bindings protect against all known attacks. The two bindings are based on TLS client certificates, and on a variant of the well-known Same Origin Policy of browsers.