AJAX-enabled Client Authentication in an Extended SaaS Architecture using Profile Binding

Dong-Soo Jeong, Krislan B. Ong, Gi-Weon Kim, Jung-Gil Song · 한국정보기술학회논문지 · 2009

The majority of security attacks emanate from a weak authentication system deployed in the application. A strong authentication scheme is critical especially in an on-demand application such as Software-as-a-Service to ward off possible security threats. In this paper, we propose an unobtrusive Ajax-enabled authentication framework based on profile binding. We use the client’s profile, the client’s IP address and session time stamp as variables for the cryptographic binding. Several security standards are combined such as Message Authentication Code, S/Key OTP and SSL to provide a robust authentication framework. The proposed authentication framework will then be used in an extended SaaS model which is an alternative solution to security challenge confronting many SaaS providers.

Read the paper · More papers on PaperTik