activity
20142017
most citedA Comprehensive Formal Security Analysis of OAuth 2.0

35 citations · 53 across the 3 of their papers we have counts for

collaborators

5 papers

cs.CR2017

The Web SSO Standard OpenID Connect: In-Depth Formal Security Analysis and Security Guidelines

Daniel Fett, Ralf Kuesters, Guido Schmitz

Web-based single sign-on (SSO) services such as Google Sign-In and Log In with Paypal are based on the OpenID Connect protocol. This protocol enables so-called relying parties to d…

cs.CR2016★ 35 cited

A Comprehensive Formal Security Analysis of OAuth 2.0

Daniel Fett, Ralf Kuesters, Guido Schmitz

The OAuth 2.0 protocol is one of the most widely deployed authorization/single sign-on (SSO) protocols and also serves as the foundation for the new SSO standard OpenID Connect. De…

cs.CR2015★ 9 cited

SPRESSO: A Secure, Privacy-Respecting Single Sign-On System for the Web

Daniel Fett, Ralf Kuesters, Guido Schmitz

Single sign-on (SSO) systems, such as OpenID and OAuth, allow web sites, so-called relying parties (RPs), to delegate user authentication to identity providers (IdPs), such as Face…

cs.CR2014

Analyzing the BrowserID SSO System with Primary Identity Providers Using an Expressive Model of the Web

Daniel Fett, Ralf Kuesters, Guido Schmitz

BrowserID is a complex, real-world Single Sign-On (SSO) System for web applications recently developed by Mozilla. It employs new HTML5 features (such as web messaging and web stor…

cs.CR2014★ 9 cited

An Expressive Model for the Web Infrastructure: Definition and Application to the BrowserID SSO System

Daniel Fett, Ralf Kuesters, Guido Schmitz

The web constitutes a complex infrastructure and as demonstrated by numerous attacks, rigorous analysis of standards and web applications is indispensable. Inspired by successful p…