Publication: On the security of SSL/TLS-enabled applications
dc.contributor.affiliation | DA-IICT, Gandhinagar | |
dc.contributor.author | Samdaria, Navkar | |
dc.contributor.author | Das, Maniklal | |
dc.contributor.researcher | Samdaria, Navkar (200501174) | |
dc.date.accessioned | 2025-08-01T13:09:05Z | |
dc.date.issued | 01-01-2014 | |
dc.description.abstract | SSL/TLS (Secure Socket Layer/Transport Layer Security)-enabled web applications aim to provide�public key certificate�based�authentication, secure�session key establishment, and symmetric key based traffic confidentiality. A large number of electronic�commerce applications, such as stock trading, banking, shopping, and gaming rely on the security strength of the SSL/TLS protocol. In recent times, a potential threat, known as main-in-the-middle (MITM) attack, has been exploited by attackers of SSL/TLS-enabled web applications, particularly when naive users want to connect to an SSL/TLS-enabled web server. In this paper, we discuss about the MITM threat to SSL/TLS-enabled web applications. We review the existing space of solutions to counter the MITM attack on SSL/TLS-enabled applications, and then, we provide an effective solution which can resist the MITM attack on SSL/TLS-enabled applications. The proposed solution uses a soft-token based approach for�user authentication�on top of the SSL/TLS�s security features. We show that the proposed solution is secure, efficient and user friendly in comparison to other similar approaches. | |
dc.format.extent | 68-81 | |
dc.identifier.citation | Das, Manik Lal, and Navkar Samdaria, "On the security of SSL/TLS-enabled applications," Applied Computing and Informatics, vol. 10, no. 1, pp. 68-81, Jan. 2014. Doi: 10.1016/j.aci.2014.02.001 | |
dc.identifier.doi | 10.1016/j.aci.2014.02.001 | |
dc.identifier.issn | 2210-8327 | |
dc.identifier.scopus | 2-s2.0-84922433733 | |
dc.identifier.uri | https://ir.daiict.ac.in/handle/dau.ir/1626 | |
dc.language.iso | en | |
dc.publisher | Elsevier | |
dc.relation.ispartofseries | Vol. 10; No. 01-Feb | |
dc.source | Applied Computing and Informatics | |
dc.source.uri | https://www.sciencedirect.com/science/article/pii/S2210832714000039 | |
dc.title | On the security of SSL/TLS-enabled applications | |
dspace.entity.type | Publication | |
relation.isAuthorOfPublication | b5cc5527-f42b-4c08-bdc3-50c4d46603a0 | |
relation.isAuthorOfPublication.latestForDiscovery | b5cc5527-f42b-4c08-bdc3-50c4d46603a0 |