arrow
返回

Key-Based Cookie-Less Session Management Framework for Application Layer Security

delete2019-01-01
delete7
delete
OA
AI
Z
Zahoor Ahmed Alizai
H
Hasan Tahir *
M
Malik Hamza Murtaza
S
Shahzaib Tahir
K
Klaus D. McDonald-Maier
DOI:10.1109/ACCESS.2019.2940331delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
The goal of this study is to extend the guarantees provided by the secure transmission protocols such as Secure Sockets Layer (SSL) or Transport Layer Security (TLS) and apply them to the application layer. This paper proposes a comprehensive scheme that allows the unification of multiple security mechanisms, thereby removing the burden of authentication, mutual authentication, continuous authentication, and session management from the application development life-cycle. The proposed scheme will allow creation of high-level security mechanisms such as access control and group authentication on top of the extended security provisions. This scheme effectively eliminates the need for session cookies, session tokens and any similar technique currently in use. Hence reducing the attack surface and nullifying a vast group of attack vectors.
Keyword:
Authentication
multi-factor authentication
password-less authentication
application layer security
session management
cookies
tokens
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

N
national university of sciences & technology - pakistan
学者数:
7.8K
论文数: 6.6K
被引数: 6
U
University of Essex
学者数:
4.0K
论文数: 4.8K
被引数: 5