Publication:
On the security of SSL/TLS-enabled applications

dc.contributor.affiliationDA-IICT, Gandhinagar
dc.contributor.authorSamdaria, Navkar
dc.contributor.authorDas, Maniklal
dc.contributor.researcherSamdaria, Navkar (200501174)
dc.date.accessioned2025-08-01T13:09:05Z
dc.date.issued01-01-2014
dc.description.abstractSSL/TLS (Secure Socket Layer/Transport Layer Security)-enabled web applications aim to provide�public key certificate�based�authentication, secure�session key establishment, and symmetric key based traffic confidentiality. A large number of electronic�commerce applications, such as stock trading, banking, shopping, and gaming rely on the security strength of the SSL/TLS protocol. In recent times, a potential threat, known as main-in-the-middle (MITM) attack, has been exploited by attackers of SSL/TLS-enabled web applications, particularly when naive users want to connect to an SSL/TLS-enabled web server. In this paper, we discuss about the MITM threat to SSL/TLS-enabled web applications. We review the existing space of solutions to counter the MITM attack on SSL/TLS-enabled applications, and then, we provide an effective solution which can resist the MITM attack on SSL/TLS-enabled applications. The proposed solution uses a soft-token based approach for�user authentication�on top of the SSL/TLS�s security features. We show that the proposed solution is secure, efficient and user friendly in comparison to other similar approaches.
dc.format.extent68-81
dc.identifier.citationDas, Manik Lal, and Navkar Samdaria, "On the security of SSL/TLS-enabled applications," Applied Computing and Informatics, vol. 10, no. 1, pp. 68-81, Jan. 2014. Doi: 10.1016/j.aci.2014.02.001
dc.identifier.doi10.1016/j.aci.2014.02.001
dc.identifier.issn2210-8327
dc.identifier.scopus2-s2.0-84922433733
dc.identifier.urihttps://ir.daiict.ac.in/handle/dau.ir/1626
dc.language.isoen
dc.publisherElsevier
dc.relation.ispartofseriesVol. 10; No. 01-Feb
dc.sourceApplied Computing and Informatics
dc.source.urihttps://www.sciencedirect.com/science/article/pii/S2210832714000039
dc.titleOn the security of SSL/TLS-enabled applications
dspace.entity.typePublication
relation.isAuthorOfPublicationb5cc5527-f42b-4c08-bdc3-50c4d46603a0
relation.isAuthorOfPublication.latestForDiscoveryb5cc5527-f42b-4c08-bdc3-50c4d46603a0

Files

Collections