Automatic Security Analysis of SAML-Based Single Sign-On Protocols

Alessandro Armando, Roberto Carbone, Luca Compagna, Giancarlo Pellegrino · IGI Global eBooks · 2011

Single-Sign-On (SSO) protocols enable companies to establish a federated environment in which clients sign in the system once and yet are able to access to services offered by different companies. The OASIS Security Assertion Markup Language (SAML) 2.0 Web Browser SSO Profile is the emerging standard in this context. In previous work a severe security flaw in the SAML-based SSO for Google Apps was discovered. By leveraging this experience, this chapter will show that model checking techniques for security protocols can support the development and analysis of SSO solutions helping the designer not only to detect serious security flaws early in the development life-cycle but also to provide assurance on the security of the solutions identified.

Read the paper · More papers on PaperTik