Design of the Secured Profile Binding Framework on AJAX-based Technology
Rolyn C. Daguil, Woo-Yong Son, Sang-On Nam, Gi-Weon Kim, Jung-Gil Song · 한국정보기술학회논문지 · 2008
This paper proposed a novel framework for securing AJAX-based applications using a client profile binding scheme. The client profile contains the client's username and password, IP address of the client's computer, and the time stamp. The server will initially send a cryptographically random generated number as the authenticator over the SSL to the client. The client authentication handler will then compute a keyed MAC (Message Authentication Code) of the client profile using the authenticator. The bound token is a concatenation of the MAC value and the client profile. Then, the bound token will be sent back to the server over SSL and will be used to verify the account of the client. An S/key OTP (One Time Password) is then hashed in both the client and the server using a one-way function. The proposed framework also provides re-authentication scheme after a session is revoked. The revocation and renewal of sessions will be triggered in the client based on events and time. The subsequent re-authentication of the session is performed asynchronously by the XMLHttpRequest object in the browser. The profile binding proposed in this paper provides a reliable scheme for AJAX-based client authentication.