DocumentCode
569004
Title
Service provider authentication assurance
Author
Jøsang, Audun ; Varmedal, Kent A. ; Rosenberger, Christophe ; Kumar, Rajendra
Author_Institution
Univ. of Oslo, Oslo, Norway
fYear
2012
fDate
16-18 July 2012
Firstpage
203
Lastpage
210
Abstract
The concept of authentication assurance traditionally refers to the robustness of methods and mechanisms for user authentication, including the robustness of initial registration and provisioning of user credentials, as well as the robustness of mechanisms that enforce user authentication during operation. However, the user is not the only party that needs to be authenticated to ensure security of online transactions. In fact, online service provision always involves two parties, typically the user on the client side and the service provider on the server side, so that mutual authentication between the two sides is required. In contrast to the unilateral focus on user authentication by industry and academia, it is in fact equally important for the user to correctly authenticate the service provider. Unfortunately, little attention is paid to the problem of correctly authentication the service provider. This paper proposes a framework for server and service provider authentication assurance, similarly to frameworks for user authentication assurance that have already been specified, or are currently under development by many national governments.
Keywords
authorisation; client-server systems; government; client side; national governments; online service provision; online transaction; server side; service provider authentication assurance; user authentication; user credentials; Authentication; Browsers; Humans; Robustness; Servers; Usability;
fLanguage
English
Publisher
ieee
Conference_Titel
Privacy, Security and Trust (PST), 2012 Tenth Annual International Conference on
Conference_Location
Paris
Print_ISBN
978-1-4673-2323-9
Electronic_ISBN
978-1-4673-2325-3
Type
conf
DOI
10.1109/PST.2012.6297941
Filename
6297941
Link To Document