RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
HTTP Mutual authentication and Web security Yutaka OIWA SAAG, IETF - - PowerPoint PPT Presentation
HTTP Mutual authentication and Web security Yutaka OIWA SAAG, IETF 80 Prague RESEARCH CENTER FOR INFORMATION SECURITY (RCIS) NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST) Web security Its importance no need to
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
A single connection Channel setup Authentication Security setup Data Processing
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
Connection 1 Connection 2 Access web mail A ‧ auth required Send a credential ‧ access granted Want to write a mail ‧ ”new mail„ form sent to client Post a mail form ‧ server process the req.
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
Connection 1 Connection 2 Access web mail A ‧ auth required Send a credential A ‧ access granted Want to write a mail ‧ ”new mail„ Post a mail form ‧ server process the req. Read a news B ‧ auth req. Send a credential B ‧ access granted
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
transport security requests requests
Transport = application session security Authentication requests requests transport security transport security transport security requests requests requests requests requests requests requests requests
Application session
Authentication
Application session
Authentication
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
Cookie: SID=UxVwgVTWXnGVZDeGEo13PeOBK…
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)
— Authentication must be done before the URL is known to the server still works for intranet-type applications
We may need a way to use certificates wisely ‧
RESEARCH CENTER FOR INFORMATION SECURITY (RCIS)
NATIONAL INSTITUTE OF ADVANCED INDUSTRIAL SCIENCE AND TECHNOLOGY (AIST)