WANG Juan, HU Hongxin, ZHAO Bo, YAN Fei, ZHANG Huanguo, WU Qianhong. Formal Analysis of Information Card Federated Identity-Management Protocol[J]. Chinese Journal of Electronics, 2013, 22(1): 83-88.
Formal Analysis of Information Card Federated Identity-Management Protocol

Funds:  This work is supported by the National Natural Science Foundation of China (No.61003268, No.61173138) the Fundamental Research Funds for the Central Universities (No.211274629).
  • Received Date: 2011-10-01
  • Rev Recd Date: 2012-04-01
  • Publish Date: 2013-01-05
  • Information Card (InfoCard) is a usercentric identity management metasystem. It has been accepted as a standard of OASIS Identity Metasystem Interoperability Technical Committee. However, there is currently a lack of security analysis to InfoCard protocol, especially, with formal methods. In this paper, we accommodate such a requirement by analyzing security properties of InfoCard protocol adopting a formal protocol analysis tool. Our analysis result discovers that current InfoCard protocol is vulnerable against the session replay attack. Furthermore, we reveal the importance of two optional elements in InfoCard metasystem, token scope and proof key, and found that InfoCard protocol will be susceptible to manin- the-middle attack and token replay attack if these two optional elements lack.
