C-Verifier: Understanding and Formally Verifying Cross-Service Flaws in AWS Cognito
Zhen Chen, Ze Jin, Le Gong, Kexin Chen, Xiangyi Zeng, Qixu Liu
Abstract
Managed cloud-identity services issue short-lived credentials so that mobile and web clients can access storage, database, and serverless APIs without passing through application servers. These services are layered on top of a security-token engine and an account-wide policy system, yet prior work has examined each layer in isolation. We present the first end-to-end analysis of this multi-plane workflow, using Amazon Cognito as a representative case. Treating Cognito, the Security Token Service and IAM as a single security graph, we (i) provide the first in-depth security analysis of session-bypass risk and (ii) uncover two additional design flaws that allow users to exploit overly permissive or divergent trust policies and to assume “hanging” roles left behind after reconfiguration. A crawl of Cognito-backed Android apps reveals these flaws in 179 deployments, affecting at least 1.7 million users. To detect such drift automatically, we build C-Verifier, a tool that converts an account snapshot into Satisfiability Modulo Theories formulas spanning all three control planes and checks five security properties. C-Verifier yields precise counter-examples, outperforms four state-of-the-art tools, and analyzes 400 identity pools with 1,400 roles in under 40 s. We release both the tool and a curated benchmark, Cognito Configuration Bench, to facilitate reproducible cross-service policy research.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get aef4bc40-0990-4de8-8a67-6321181c6a4aRelated papers
- Detecting Multi-Step IAM Attacks in AWS Environments via Model CheckingIlia Shevrin, Oded MargalitUSENIX Security 2023
- Demystifying the (In)Security of Oauth-Based Account Linking in Connector EcosystemsKaixuan Luo, Xianbo Wang, Adonis P. H. Fung, Wing Cheong LauS&P 2026
- P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access PoliciesZe Jin, Luyi Xing, Yiwei Fang, Yan Jia et al.CCS 2022 · 19 citations
- GRASP: Hardening Serverless Applications through Graph Reachability Analysis of Security PoliciesIsaac Polinsky, Pubali Datta, Adam Bates, William EnckWWW 2024 · 15 citations
- Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile AppsChaoshun Zuo, Zhiqiang Lin, Yinqian ZhangS&P 2019 · 123 citations
