A cloud application uses a third-party identity provider (IdP) for SSO. The security team notices that tokens are being reused across different applications. Which token binding mechanism should be implemented?
Trap 1: Use of bearer tokens without additional protection
Bearer tokens are easily reusable.
Trap 2: Short token expiration times
Short expiration reduces but does not prevent reuse during validity.
Trap 3: Audience restriction
Audience restricts which service can accept the token, not binding.
- A
Use of bearer tokens without additional protection
Why it fails: Bearer tokens are easily reusable.
- B
Short token expiration times
Why it fails: Short expiration reduces but does not prevent reuse during validity.
- C
Token binding to TLS session
Token binding ties the token to a specific TLS connection.
- D
Audience restriction
Why it fails: Audience restricts which service can accept the token, not binding.