Service Provider Authentication Assurance - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2012

Service Provider Authentication Assurance

Résumé

The concept of authentication assurance traditionally refers to the robustness of methods and mechanisms for user authentication, including the robustness of initial registration and provisioning of user credentials, as well as the robustness of mechanisms that enforce user authentication during operation. However, the user is not the only party that needs to be authenticated to ensure security of online transactions. In fact, online service provision always involves two parties, typically the user on the client side and the service provider on the server side, so that mutual authentication between the two sides is required. In contrast to the unilateral focus on user authentication by industry and academia, it is in fact equally important for the user to correctly authenticate the service provider. Unfortunately, little attention is paid to the problem of correctly authentication the service provider. This paper proposes a framework for server and service provider authentication assurance, similarly to frameworks for user authentication assurance that have already been specified, or are currently under development by many national governments.
Fichier principal
Vignette du fichier
acti-josang-2012-1.pdf (261.06 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00998929 , version 1 (03-06-2014)

Identifiants

  • HAL Id : hal-00998929 , version 1

Citer

Audun Josang, Kent A. Vardemal, Christophe Rosenberger, Rajendra Kumar. Service Provider Authentication Assurance. International Conference on Privacy, Security and Trust (PST), 2012, Paris, France. 8 p. ⟨hal-00998929⟩
112 Consultations
274 Téléchargements

Partager

Gmail Facebook X LinkedIn More