Toward Automated Formal Security Analysis of SAML V2.0 Web Browser SSO Standard—The POST/Artifact Use Case

2Citations
Citations of this article
6Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Single Sign-On (SSO) protocols streamline user authentication with a unified login for multiple online services, improving usability and security. One of the most common SSO protocol frameworks — the Security Assertion Markup Language V2.0 (SAML) Web SSO Profile — has been in use for more than two decades, primarily in government, education and enterprise environments. Despite its mission-critical nature, only certain deployments and configurations of the Web SSO Profile have been formally analyzed. This paper attempts to bridge this gap by performing a comprehensive formal security analysis of the SAML V2.0 SP-initiated SSO with POST/Artifact Bindings use case. Rather than focusing on a specific deployment and configuration, we closely follow the specification with the goal of capturing many different deployments allowed by the standard. Modeling and analysis are performed using Tamarin prover — state-of-the-art tool for automated verification of security protocols in the symbolic model of cryptography. Technically, we build a meta-model of the use case that we instantiate to eight different protocol variants. Using the Tamarin prover, we formally verify a number of critical security properties for those protocol variants, while identifying certain drawbacks and potential vulnerabilities.

Cite

CITATION STYLE

APA

Hartl, Z., & Derek, A. (2025). Toward Automated Formal Security Analysis of SAML V2.0 Web Browser SSO Standard—The POST/Artifact Use Case. IEEE Access, 13, 180126–180144. https://doi.org/10.1109/ACCESS.2025.3622379

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free