English
Related papers

Related papers: The Web SSO Standard OpenID Connect: In-Depth Form…

200 papers

Many millions of users routinely use their Google accounts to log in to relying party (RP) websites supporting the Google OpenID Connect service. OpenID Connect, a newly standardised single-sign-on protocol, builds an identity layer on top…

Cryptography and Security · Computer Science 2015-08-10 Wanpeng Li , Chris J Mitchell

The OAuth 2.0 protocol is one of the most widely deployed authorization/single sign-on (SSO) protocols and also serves as the foundation for the new SSO standard OpenID Connect. Despite the popularity of OAuth, so far analysis efforts were…

Cryptography and Security · Computer Science 2019-01-31 Daniel Fett , Ralf Kuesters , Guido Schmitz

OAuth is the new de facto standard for delegating authorization in the web. An important limitation of OAuth is the fact that it was designed for authorization and not for authentication. The usage of OAuth for authentication thus leads to…

Cryptography and Security · Computer Science 2016-01-08 Vladislav Mladenov , Christian Mainka , Jörg Schwenk

Single sign-on (SSO) systems, such as OpenID and OAuth, allow web sites, so-called relying parties (RPs), to delegate user authentication to identity providers (IdPs), such as Facebook or Google. These systems are very popular, as they…

Cryptography and Security · Computer Science 2015-08-10 Daniel Fett , Ralf Kuesters , Guido Schmitz

BrowserID is a complex, real-world Single Sign-On (SSO) System for web applications recently developed by Mozilla. It employs new HTML5 features (such as web messaging and web storage) and cryptographic assertions to provide decentralized…

Cryptography and Security · Computer Science 2019-01-31 Daniel Fett , Ralf Kuesters , Guido Schmitz

Single Sign-On (SSO) systems simplify login procedures by using an an Identity Provider (IdP) to issue authentication tokens which can be consumed by Service Providers (SPs). Traditionally, IdPs are modeled as trusted third parties. This is…

Cryptography and Security · Computer Science 2014-12-05 Christian Mainka , Vladislav Mladenov , Jörg Schwenk

OpenID Connect (OIDC) enables a user with commercial-off-the-shelf browsers to log into multiple websites, called relying parties (RPs), by her username and credential set up in another trusted web system, called the identity provider…

Cryptography and Security · Computer Science 2025-07-02 Jingqiang Lin , Baitao Zhang , Wei Wang , Quanwei Cai , Jiwu Jing , Huiyang He

Approved client-server authentication mechanisms are described for the IVOA single-sign-on profile: No Authentication; HTTP Basic Authentication; TLS with passwords; TLS with client certificates; Cookies; Open Authentication; Security…

Instrumentation and Methods for Astrophysics · Physics 2019-06-05 Giuliano Taffoni , André Schaaff , Guy Rixon , Brian Major

Millions of users routinely use Google to log in to websites supporting OAuth 2.0 or OpenID Connect; the security of OAuth 2.0 and OpenID Connect is therefore of critical importance. As revealed in previous studies, in practice RPs often…

Cryptography and Security · Computer Science 2019-01-28 Wanpeng Li , Chris J Mitchell , Thomas Chen

Social authentication has been suggested as a usable authentication ceremony to replace manual key authentication in messaging applications. Using social authentication, chat partners authenticate their peers using digital identities…

Cryptography and Security · Computer Science 2024-02-06 Felix Linker , David Basin

Self-Sovereign Identity (SSI), as a new and promising identity management paradigm, needs mechanisms that can ease a gradual transition of existing services and developers towards it. Systems that bridge the gap between SSI and established…

Cryptography and Security · Computer Science 2024-01-19 Felix Hoops , Florian Matthes

Authentication and authorization are two key elements of a software application. In modern day, OAuth 2.0 framework and OpenID Connect protocol are widely adopted standards fulfilling these requirements. These protocols are implemented into…

Cryptography and Security · Computer Science 2018-08-21 Kavindu Dodanduwa , Ishara Kaluthanthri

The web constitutes a complex infrastructure and as demonstrated by numerous attacks, rigorous analysis of standards and web applications is indispensable. Inspired by successful prior work, in particular the work by Akhawe et al. as well…

Cryptography and Security · Computer Science 2019-01-31 Daniel Fett , Ralf Kuesters , Guido Schmitz

Many millions of users routinely use their Google, Facebook and Microsoft accounts to log in to websites supporting OAuth 2.0 and/or OpenID Connect-based single sign on. The security of OAuth 2.0 and OpenID Connect is therefore of critical…

Cryptography and Security · Computer Science 2018-01-25 Wanpeng Li , Chris J Mitchell , Thomas Chen

Single Sign-On (SSO) protocols streamline user authentication with a unified login for multiple online services, improving usability and security. One of the most common SSO protocol frameworks - the Security Assertion Markup Language V2.0…

Cryptography and Security · Computer Science 2026-01-21 Zvonimir Hartl , Ante Đerek

Web3's decentralised infrastructure has upended the standardised approach to digital identity established by protocols like OpenID Connect. Web2 and Web3 currently operate in silos, with Web2 leveraging selective disclosure JSON web tokens…

Cryptography and Security · Computer Science 2025-01-24 Ben Biedermann , Matthew Scerri , Victoria Kozlova , Joshua Ellul

The number of login options on web sites has increased since the introduction of web single sign-on (SSO) protocols. Web SSO services allow users to grant web sites or relying parties (RPs) access to their personal profile information from…

Cryptography and Security · Computer Science 2024-12-23 Srivathsan G. Morkonda , Sonia Chiasson , Paul C. van Oorschot

We perform a comprehensive analysis and comparison of 14 web single sign-on (SSO) systems proposed and/or deployed over the last decade, including federated identity and credential/password management schemes. We identify common design…

Cryptography and Security · Computer Science 2020-08-11 Furkan Alaca , Paul C. van Oorschot

OpenID Connect (OIDC) is a widely used authentication standard for the Web. In this work, we define a new Identity Certification Token (ICT) for OIDC. An ICT can be thought of as a JSON-based, short-lived user certificate for end-to-end…

Cryptography and Security · Computer Science 2024-06-13 Jonas Primbs , Michael Menth

Single sign-on (SSO) allows a user to maintain only the credential for an identity provider (IdP) to log into multiple relying parties (RPs). However, SSO introduces privacy threats, as (a) a curious IdP could track a user's all visits to…

Cryptography and Security · Computer Science 2025-03-27 Chengqian Guo , Jingqiang Lin , Quanwei Cai , Wei Wang , Wentian Zhu , Jiwu Jing , Qiongxiao Wang , Bin Zhao , Fengjun Li
‹ Prev 1 2 3 10 Next ›