Rolf Oppliger, Ralf Hauser, David A. Basin: SSL/TLS session-aware user authentication - Or how to effectively thwart the man-in-the-middle. Comput. Commun. 29(12): 2238-2246 (2006)