Additional Security at Login: New Plugin for the Shibboleth IdP
When users log in to web applications, sensitive credentials are transmitted between the browser and the server. HTTPS already protects this communication during transmission. However, additional layers of security can help further strengthen the access management infrastructure.
To this end, DAASI International developed a plugin for the Shibboleth Identity Provider on behalf of FH Aachen. The plugin extends the existing login process by adding an additional layer of encryption for the password entered by the user.
In the standard login process, the username and password are transmitted to the server over an HTTPS-encrypted connection. The new plugin extends this protection at the application level: once the password has been entered and the login form submitted, the password is additionally encrypted directly in the browser before being sent to the Shibboleth IdP over the HTTPS connection. The IdP’s encryption certificate can, for example, be used for this additional encryption. This means that the password is additionally encrypted during transmission, independently of the already protected HTTPS transport channel.
The plugin provides additional protection in the event that an attacker gains access to the TLS-encrypted communication. This could occur, for example, through a manipulated or incorrectly installed root certificate, or through access to a load balancer, reverse proxy, or other network component in front of the IdP where TLS encryption is terminated. Even in such a scenario, the password remains encrypted by the plugin and cannot be read by the attacker. On the server side, the Shibboleth IdP then decrypts the password using the corresponding private key. Validation subsequently takes place as usual. The existing authentication process does not need to be fundamentally changed.
The plugin can be integrated into existing Shibboleth environments with comparatively few modifications. It therefore provides a way to add another layer of security to existing access management infrastructures without having to fundamentally redesign the existing login process.
In keeping with our open-source approach, we are making the plugin publicly available with the consent of FH Aachen. This enables the community to review, use and further develop the solution.


