ArticleslgStudy

science

Token Binding

Token Binding is a science topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand Token Binding rather than just read about it. In short: Token Binding is a proposed standard for a Transport Layer Security (TLS) extension that aims to increase TLS security by using cryptographic certificates on both ends of the TLS connection. Current practice often depends on bearer tokens, which may be lost or stolen.

Key takeaways

  • Token Binding belongs to science; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect Token Binding to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of Token Binding from memory before moving on to harder problems.

Reference excerpt

Token Binding is a proposed standard for a Transport Layer Security (TLS) extension that aims to increase TLS security by using cryptographic certificates on both ends of the TLS connection. Current practice often depends on bearer tokens, which may be lost or stolen. Bearer tokens are also vulnerable to man-in-the-middle attacks or replay attacks. In contrast, bound tokens are established by a user agent that generates a private-public key pair per target server, providing the public key to the server, and thereafter proving possession of the corresponding private key on every TLS connection to the server. Token Binding is an evolution of the Transport Layer Security Channel ID (previously known as Transport Layer Security – Origin Bound Certificates (TLS-OBC)) extension. Industry participation is widespread with standards contributors including Microsoft, Google, PayPal, Ping Identity, and Yubico. Browser support remains limited, however. Only the older version of Microsoft Edge using the Blink engine had support for Token Binding. Chromium removed support for Token Binding in version 70.

IETF standards The following group of IETF RFCs and Internet Drafts comprise a set of interrelated specifications for implementing different aspects of the Token Binding standard.

The Token Binding Protocol Version 1.0. Allows client/server applications to create long-lived, uniquely identifiable TLS bindings spanning multiple TLS sessions and connections. Applications are then enabled to cryptographically bind security tokens to the TLS layer, preventing token export and replay attacks. To protect privacy, the Token Binding identifiers are only conveyed over TLS and can be reset by the user at any time. Transport Layer Security (TLS) Extension for Token Binding Protocol Negotiation. Extension for the negotiation of Token Binding protocol version and key parameters. Token Binding over HTTP. A collection of mechanisms that allow HTTP servers to cryptographically bind security tokens (such as cookies and OAuth tokens) to TLS connections. Token Binding for Transport Layer Security (TLS) Version 1.3 Connections. This companion document defines a backwards compatible way to negotiate Token Binding on TLS 1.3 connections. HTTPS Token Binding with TLS Terminating Reverse Proxies. Defines HTTP header fields that enable a TLS terminating reverse proxy to convey information to a backend server about the validated Token Binding Message received from a client, which enables that backend server to bind, or verify the binding of, cookies and other security tokens to the client's Token Binding key. This facilitates the reverse proxy and backend server functioning together as though they are a single logical server side deployment of HTTPS Token Binding. Related IETF draft standard:

OAuth 2.0 Token Binding. Enables OAuth 2.0 implementations to apply Token Binding to Access Tokens, Authorization Codes, Refresh Tokens, JWT Authorization Grants, and JWT Client Authentication. This cryptographically binds these tokens to a client's Token Binding key pair, possession of which is proven on the TLS connections over which the tokens are intended to be used. This use of Token Binding protects these tokens from man-in-the-middle and token export and replay attacks.

Related standards The use of TLS Token Binding allows for more robust web authentication. Several web authentication standards developed by standards bodies outside of IETF are adopting the draft standards.

Draft OpenID Connect Token Bound Authentication 1.0. OpenID Connect (OIDC) is a simple identity layer on top of the OAuth 2.0 protocol. OIDC enables Clients to verify the identity of the End-User based on the authentication performed by an Authorization Server, as well as to obtain basic profile information about the End-User in an interoperable, REST-like manner. The OIDC Token Bound Authentication specification enables OIDC implementations to apply Token Binding to the OIDC ID Token. This cryptographically binds the ID Token to the TLS connection over which the authentication occurred. This use of Token Binding protects the authentication flow from man-in-the-middle and token export and replay attacks. W3C Recommendation for Web Authentication: An API for accessing Public Key Credentials. Web Authentication (WebAuthn), an interface for public-key authentication of users to web-based applications and services, removed support for Token Binding in version L3.

References

External links Token Binding at BrowserAuth.net Token Binding Presentation at Identiverse 2018 Klingenstein, Nate; Scavo, Tom (August 10, 2010). "SAML V2.0 Holder-of-Key Web Browser SSO Profile". OASIS. Retrieved August 23, 2018. OAuth 2.0 Token Binding Blog

Worked examples

Example 1 — a first encounter with Token Binding

Start with the simplest possible case. Write down what Token Binding claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In science, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to Token Binding before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about Token Binding ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of Token Binding

In research
Token Binding appears in science research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses Token Binding in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
Token Binding is common in secondary-school and first-year university syllabi. It links to neighbouring topics Internet Standards, Security, Transport Layer Security, so understanding it makes those chapters shorter.
In everyday life
Look for Token Binding outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study Token Binding in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what Token Binding means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain Token Binding out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is Token Binding in simple terms?

Token Binding is a proposed standard for a Transport Layer Security (TLS) extension that aims to increase TLS security by using cryptographic certificates on both ends of the TLS connection. Current practice often depends on bearer tokens, which may be lost or stolen.

Why does Token Binding matter?

Because it connects several science ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study Token Binding?

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on Token Binding.

Tags

  • Internet Standards
  • Security
  • Transport Layer Security

Keep exploring