Improvement of OpenID Connect protocol and its security analysis

LU Jintian, YAO Lili, HE Xudong, MENG Bo   

  1. College of Computer Science, South-Central University for Nationalities, Wuhan Hubei 430074, China
  • Received:2016-10-08 Revised:2016-12-28 Online:2017-05-10 Published:2017-05-16
  • Supported by:
    This work is partially supported by the National Natural Science Foundation of China (61272497), the Natural Science Foundation of Hubei Province (2014CFB249).

改进的OpenID Connect协议及其安全性分析

鲁金钿, 尧利利, 何旭东, 孟博   

  1. 中南民族大学 计算机科学学院, 武汉 430074
  • 通讯作者: 孟博
  • 作者简介:鲁金钿(1991-),男,湖南湘西人,硕士研究生,主要研究方向:网络协议形式化及逆向分析;尧利利(1993-),女,江西抚州人,硕士研究生,主要研究方向:数据存储安全;何旭东(1991-),男,湖北武汉人,硕士研究生,主要研究方向:安全体系结构与协议;孟博(1974-),男,河北石家庄人,教授,博士,主要研究方向:网络空间安全。
  • 基金资助:

Abstract: OpenID Connect protocol is widely used in identity authentication field and is one of the newest single sign-on protocols. In this paper, the digital signature and asymmetric encryption were used to improve OpenID connect protocol. The secrecy and authentication of the improved protocol were focused. And then the improved OpenID connect protocol was formalized with the applied PI calculus in the symbolic model, next the secrecy was modeled by query and the authentication was modeled by non-injective relations to test the secrecy and authentication of improved OpenID Connect protocol. Finally the formal model of the OpenID Connect protocol was transformed into the input of the automatic tool ProVerif based on symbol model. The results indicate that the improved OpenID Connect protocol is authenticable and secret.

Key words: aasymmetric encryption, digital signature, authentication, symbol model, formal method, ProVerif

摘要: OpenID Connect协议是最新的单点登录协议之一,已经广泛应用于用户身份认证领域,其安全性受到了人们的重点关注。为增强OpenID Connect协议的安全性,首先引入数字签名及非对称加密技术,对其进行改进,重点关注改进后协议的秘密性和认证性;其次基于符号模型,应用应用PI演算对改进的OpenID Connect协议进行形式化建模;然后为验证改进后协议的认证性和秘密性,分别使用非单射性和query对认证性和秘密性进行建模;最后把改进的OpenID Connect协议的应用PI演算模型转换为安全协议分析工具ProVerif的输入,应用ProVerif对其进行形式化分析。实验结果表明,改进后的OpenID Connect协议具有认证性和秘密性。

关键词: 非对称加密, 数字签名, 认证性, 符号模型, 形式化方法, ProVerif

