DocumentCode :
3269431
Title :
Secure session management with cookies
Author :
Pujolle, Guy ; Serhrouchni, Ahmed ; Ayadi, Ines
Author_Institution :
Lip6, Univ. Pierre et Marie Curie, Paris, France
fYear :
2009
fDate :
8-10 Dec. 2009
Firstpage :
1
Lastpage :
6
Abstract :
HTTP (hypertext transfer protocol) is a stateless protocol widely used in Internet World Wide Web. The idea behind a stateless design is to simplify the server conception because there is no need to dynamically allocate storage to deal with conversations in progress. If a client dies in mid-transaction, no part of the system needs to be responsible for cleaning the present state of the server. However, this forces Web developers to use alternative methods to authenticate HTTP requests and to maintain users´ states. A common method for solving this problem involves sending and receiving cookies. Such mechanism implies a serious security threats. Some secure cookie solutions have been proposed in literature, but still vulnerable, particularly to replay attacks. In this paper, we propose a secure cookie mechanism that implements an intermediary reverse Proxy patterns to ensure users´ sessions management and to provide the following security services: source authentication, integrity control and no-replay attacks.
Keywords :
Internet; client-server systems; computer network management; computer network security; message authentication; transport protocols; HTTP request authentication; Internet World Wide Web; Web developers; dynamically storage allocation; hypertext transfer protocol; intermediary reverse Proxy patterns; secure cookie mechanism; secure session management; security services; source authentication; Authentication; Cleaning; Filters; Internet; Protocols; Service oriented architecture; Telecommunication traffic; Traffic control; Web server; Web sites; Cookies; HMAC; HTTP; Replay attacks; Reverse Proxy; SSO architecture; Sessions management;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information, Communications and Signal Processing, 2009. ICICS 2009. 7th International Conference on
Conference_Location :
Macau
Print_ISBN :
978-1-4244-4656-8
Electronic_ISBN :
978-1-4244-4657-5
Type :
conf
DOI :
10.1109/ICICS.2009.5397550
Filename :
5397550
Link To Document :
بازگشت