Browse > Article

The proposal of improved secure cookies system based on public-key certificate  

양종필 (부경대학교 전자계산학과)
이경현 (부경대학교 전자컴퓨터정보통신공학부)
Abstract
The HTTP does not support continuity for browser-server interaction between successive visits or a user due to a stateless feature. Cookies were invented to maintain continuity and state on the Web. Because cookies are transmitted in plain and contain text-character strings encoding relevant information about the user, the attacker can easily copy and modify them for his undue profit. In this paper, we design a secure cookies scheme based on X.509 public key certificate for solving these security weakness of typical web cookies. Our secure cookies scheme provides not only mutual authentication between client and server but also confidentiality and integrity of user information. Additionally, we implement our secure cookies scheme and compare it to the performance with SSL(Secure Socket Layer) protocol that is widely used for security of HTTP environment.
Keywords
Citations & Related Records
연도 인용수 순위
  • Reference
1 /
[] /
2 /
[] / Sun Microsystems, Inc.
3 /
[] / Sun Microsystems, Inc.
4 Secure Cookies on the Web /
[ Joon S.Park;Ravi Sandhu ] / IEEE Internet Computing
5 /
[ Scott Oaks ] / Java Security, 2nd Edition
6 /
[] / PERSISTENT CLIENT STATE
7 /
[] /
8 Enhancing the securiy of cookies /
[ V.Khu smith ;C.J.Mitchell;K.Kim(ed.) ] / Information Security and Cryptology-ICISC 2001- Proceedings of the 4th International Conference, Seoul, Korea, Decomber 2001