Welcome to Journal of University of Chinese Academy of Sciences,Today is
Research Articles

Secure cross-document messaging scheme based on HTML5

  • LI Xiao-Yu ,
  • ZHANG Yu-Qing ,
  • LIU Qi-Xu ,
  • ZHENG Chen
Expand
  • National Computer Network Instrusion Protection Center, Graduate University, Chinese Academy of Sciences, Beijing 100049, China

Received date: 2011-12-09

  Revised date: 2012-03-22

  Online published: 2013-01-15

Abstract

We analyze security risk of the current cross-document messaging methods based on HTML5 and propose a secure cross-document messaging scheme SafePM. In SafePM, white list, two-way detection, and auto-detecting are developed to limit maliciously messaging. Moreover, with the detection of the message content, SafePM eliminates information leakage and tampering and reduce the risk for executing of cross-site scripts, which makes cross-document messaging more secure.

Cite this article

LI Xiao-Yu , ZHANG Yu-Qing , LIU Qi-Xu , ZHENG Chen . Secure cross-document messaging scheme based on HTML5[J]. Journal of University of Chinese Academy of Sciences, 2013 , 30(1) : 124 -130 . DOI: 10.7523/j.issn.1002-1175.2013.01.019

References

[1] Barth A, Jackson C, Mitchell J C. Securing frame communication in browsers[C]//Proceedings of the 17th USENIX Security Symposium. San Jose, CA, USA,2008:17-30.

[2] The World Wide Web Consortium (W3C).W3C editor's draft[EB/OL]. (2011-11-20)[2011-11-25]. http://dev.w3.org/html5 /postmsg/#dom-messageevent-source.

[3] Alman B. jQuery postMessage: Cross-domain scripting goodness[EB/OL]. (2009-08-23)[2011-11-20]. http://benalman. com/projects/jquery-postmessage-plugin/.

[4] Kinsey Φ S. Easy cross-site scripting using the easyXDM library[EB/OL].(2009-08-17)[2011-11-25]. http://www.codeproject.com/Articles/37622/Easy-Cross-site-Scripting-using-the-easyXDM-Library.

[5] Matono A, Nakamura A, Kojima I. A mashup tool for cross-domain Web applications using HTML5[J]. Lecture Notes in Computer Science, 2011, 6612:382-385.

[6] Ryck P D, Desmet L, Philippaerts P, et al. A security analysis of next generation Web standards[R/OL].Greece: European Network and Information Security Agency (ENISA), (2011-07-31)[2011-11-25]. http://www.enisa.europa.eu/activities/application-security/web-security/.

[7] Hickson I. HTML living standard . USA:The Web Hypertext Application Technology Working Group, (2009-10-23)[2011-11-25]http://www.whatwg.org/specs/web-apps/current-work/multipage/web-messaging.html#crossDocumentMess ages.

[8] Hanna S, Shin E C R, Akhawe D, et al. The emperor’s new APIs: on the (in)secure usage of new client-side primitives[C]//Proceedings of the 4th Web 2.0 Security and Privacy. Oakland, California, USA, 2010.

[9] Saxena P, Hanna S, Poosankam P, et al. FLAX:systematic discovery of client-side validation vulnerabilities in rich Web applications[C]//Proceedings of the 17th Annual Network & Distributed System Security Symposium. San Diego, Califonia, USA, 2010.

[10] Edwards D. Packer version 3.0[CP/OL]. (2007-04-01)[2011-11-20]. http://dean.edwards.name/weblog/2007/04/packer3/.

[11] Heiderich M. HTML5 security cheatsheet[EB/OL].(2011-01-22)[2011-11-20].http://html5sec.org/.

Outlines

/