activity
20152021
most citedMitigating CSRF attacks on OAuth 2.0 and OpenID Connect

5 citations · 13 across the 9 of their papers we have counts for

collaborators
Showing cs.CRShow all

12 papers · 1 filter

cs.CR2021

The (in)security of some recently proposed lightweight key distribution schemes

Chris J Mitchell

Two recently published papers propose some very simple key distribution schemes designed to enable two or more parties to establish a shared secret key with the aid of a third part…

cs.CR2020

Two closely related insecure noninteractive group key establishment schemes

Chris J Mitchell

Serious weaknesses in two very closely related group authentication and group key establishment schemes are described. Simple attacks against the group key establishment part of th…

cs.CR2020

Who Needs Trust for 5G?

Chris J Mitchell

There has been much recent discussion of the criticality of the 5G infrastructure, and whether certain vendors should be able to supply 5G equipment. The key issue appears to be ab…

cs.CR2020

How not to secure wireless sensor networks revisited: Even if you say it twice it's still not secure

Chris J Mitchell

Two recent papers describe almost exactly the same group key establishment protocol for wireless sensor networks. Quite part from the duplication issue, we show that both protocols…

cs.CR20192 cited

The Saeed-Liu-Tian-Gao-Li authenticated key agreement protocol is insecure

Chris J Mitchell

A recently proposed authenticated key agreement protocol is shown to be insecure. In particular, one of the two parties is not authenticated, allowing an active man in the middle o…

cs.CR20194 cited

OAuthGuard: Protecting User Security and Privacy with OAuth 2.0 and OpenID Connect

Wanpeng Li, Chris J Mitchell, Thomas Chen

Millions of users routinely use Google to log in to websites supporting OAuth 2.0 or OpenID Connect; the security of OAuth 2.0 and OpenID Connect is therefore of critical importanc…