issues
search
ietf-wg-gnap
/
gnap-core-protocol
143
stars
26
forks
source link
Security Consideration: Cuckoo Token Mitigations
#354
Closed
jricher
closed
2 years ago
jricher
commented
2 years ago
Client instance uses different keys with each AS
Stolen token bound to different keys, RS will reject
Client has strong binding between RS and AS used
Attacker can’t convince client to use “wrong” AS