loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Authors: Pascal Wichmann ; Sam Ansari ; Hannes Federrath and Jens Lindemann

Affiliation: Universität Hamburg, Germany

Keyword(s): Code Authenticity, Web Applications, Client-Side Security, Web Security.

Abstract: We present the WebAppAuth architecture for protecting client-side web applications even from attackers who fully control the web server. WebAppAuth signs all files sent to the client on a secure offline device or a hardware security module never accessible by the web server. Public keys are propagated through a key registry that is maintained by two independent key registration authorities, thus protecting users even on their first visit to the web application. Our threat model covers attackers who gain full control over the targeted domain and its DNS and DNSSEC configuration.

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.137.218.215

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Wichmann, P.; Ansari, S.; Federrath, H. and Lindemann, J. (2023). WebAppAuth: An Architecture to Protect from Compromised First-Party Web Servers. In Proceedings of the 20th International Conference on Security and Cryptography - SECRYPT; ISBN 978-989-758-666-8; ISSN 2184-7711, SciTePress, pages 548-556. DOI: 10.5220/0012141700003555

@conference{secrypt23,
author={Pascal Wichmann. and Sam Ansari. and Hannes Federrath. and Jens Lindemann.},
title={WebAppAuth: An Architecture to Protect from Compromised First-Party Web Servers},
booktitle={Proceedings of the 20th International Conference on Security and Cryptography - SECRYPT},
year={2023},
pages={548-556},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0012141700003555},
isbn={978-989-758-666-8},
issn={2184-7711},
}

TY - CONF

JO - Proceedings of the 20th International Conference on Security and Cryptography - SECRYPT
TI - WebAppAuth: An Architecture to Protect from Compromised First-Party Web Servers
SN - 978-989-758-666-8
IS - 2184-7711
AU - Wichmann, P.
AU - Ansari, S.
AU - Federrath, H.
AU - Lindemann, J.
PY - 2023
SP - 548
EP - 556
DO - 10.5220/0012141700003555
PB - SciTePress