Published November 21, 2025 | Version v1
Journal article Open

Enhancing Security Testing for Identity Management Implementations: Introducing Micro-Id-Gym Language and Micro-Id-Gym Testing Tool

  • 1. ROR icon Fondazione Bruno Kessler

Description

This work presents MIG-L, a declarative language for specifying security and conformance tests, and MIG-T, an automated testing tool for Identity Management (IdM) implementations based on SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC). MIG-L enables the systematic description of protocol behaviors and security requirements, while MIG-T executes automated assessments to verify compliance with Best Current Practices, detect known vulnerabilities, and provide actionable mitigation strategies. The combined framework supports comprehensive testing of authentication and authorization flows in federated identity ecosystems. Experimental evaluations demonstrate the flexibility, scalability, and effectiveness of the approach for improving the security posture of real-world IdM deployments.

Files

2024-2.pdf

Files (425.6 kB)

Name Size Download all
md5:a938d7694d854cb1c8c6ec009095ecc1
425.6 kB Preview Download