中文
相关论文

相关论文: Analyzing the BrowserID SSO System with Primary Id…

200 篇论文

The web constitutes a complex infrastructure and as demonstrated by numerous attacks, rigorous analysis of standards and web applications is indispensable. Inspired by successful prior work, in particular the work by Akhawe et al. as well…

密码学与安全 · 计算机科学 2019-01-31 Daniel Fett , Ralf Kuesters , Guido Schmitz

Single sign-on (SSO) systems, such as OpenID and OAuth, allow web sites, so-called relying parties (RPs), to delegate user authentication to identity providers (IdPs), such as Facebook or Google. These systems are very popular, as they…

密码学与安全 · 计算机科学 2015-08-10 Daniel Fett , Ralf Kuesters , Guido Schmitz

Web-based single sign-on (SSO) services such as Google Sign-In and Log In with Paypal are based on the OpenID Connect protocol. This protocol enables so-called relying parties to delegate user authentication to so-called identity providers.…

密码学与安全 · 计算机科学 2019-01-31 Daniel Fett , Ralf Kuesters , Guido Schmitz

Single Sign-On (SSO) systems simplify login procedures by using an an Identity Provider (IdP) to issue authentication tokens which can be consumed by Service Providers (SPs). Traditionally, IdPs are modeled as trusted third parties. This is…

密码学与安全 · 计算机科学 2014-12-05 Christian Mainka , Vladislav Mladenov , Jörg Schwenk

OAuth is the new de facto standard for delegating authorization in the web. An important limitation of OAuth is the fact that it was designed for authorization and not for authentication. The usage of OAuth for authentication thus leads to…

密码学与安全 · 计算机科学 2016-01-08 Vladislav Mladenov , Christian Mainka , Jörg Schwenk

The number of login options on web sites has increased since the introduction of web single sign-on (SSO) protocols. Web SSO services allow users to grant web sites or relying parties (RPs) access to their personal profile information from…

密码学与安全 · 计算机科学 2024-12-23 Srivathsan G. Morkonda , Sonia Chiasson , Paul C. van Oorschot

The OAuth 2.0 protocol is one of the most widely deployed authorization/single sign-on (SSO) protocols and also serves as the foundation for the new SSO standard OpenID Connect. Despite the popularity of OAuth, so far analysis efforts were…

密码学与安全 · 计算机科学 2019-01-31 Daniel Fett , Ralf Kuesters , Guido Schmitz

OpenID Connect (OIDC) enables a user with commercial-off-the-shelf browsers to log into multiple websites, called relying parties (RPs), by her username and credential set up in another trusted web system, called the identity provider…

密码学与安全 · 计算机科学 2025-07-02 Jingqiang Lin , Baitao Zhang , Wei Wang , Quanwei Cai , Jiwu Jing , Huiyang He

Single sign-on (SSO) allows users to authenticate to third-party applications through a central identity provider. Despite their wide adoption, deployed SSO systems suffer from privacy problems such as user tracking by the identity…

密码学与安全 · 计算机科学 2023-12-15 Rongwu Xu , Sen Yang , Fan Zhang , Zhixuan Fang

Single Sign-On (SSO) protocols streamline user authentication with a unified login for multiple online services, improving usability and security. One of the most common SSO protocol frameworks - the Security Assertion Markup Language V2.0…

密码学与安全 · 计算机科学 2026-01-21 Zvonimir Hartl , Ante Đerek

Single sign-on (SSO) allows a user to maintain only the credential for an identity provider (IdP) to log into multiple relying parties (RPs). However, SSO introduces privacy threats, as (a) a curious IdP could track a user's all visits to…

密码学与安全 · 计算机科学 2025-03-27 Chengqian Guo , Jingqiang Lin , Quanwei Cai , Wei Wang , Wentian Zhu , Jiwu Jing , Qiongxiao Wang , Bin Zhao , Fengjun Li

Single Sign-On (SSO) shifts the crucial authentication process on a website to to the underlying SSO protocols and their correct implementation. To strengthen SSO security, organizations, such as IETF and W3C, maintain advisories to address…

密码学与安全 · 计算机科学 2023-02-03 Maximilian Westers , Tobias Wich , Louis Jannett , Vladislav Mladenov , Christian Mainka , Andreas Mayer

Password-authenticated identities, where users establish username-password pairs with individual servers and use them later on for authentication, is the most widespread user authentication method over the Internet. Although they are…

密码学与安全 · 计算机科学 2021-09-17 Pawel Szalachowski

Intrusion Detection System (IDS) is one of the security measures being used as an additional defence mechanism to prevent the security breaches on web. It has been well known methodology for detecting network-based attacks but still…

密码学与安全 · 计算机科学 2018-08-14 Nancy Agarwal , Syed Zeeshan Hussain

The FIDO2 protocol aims to strengthen or replace password authentication using public-key cryptography. FIDO2 has primarily focused on defending against attacks from afar by remote attackers that compromise a password or attempt to phish…

密码学与安全 · 计算机科学 2023-08-08 Tarun Kumar Yadav , Kent Seamons

We perform a comprehensive analysis and comparison of 14 web single sign-on (SSO) systems proposed and/or deployed over the last decade, including federated identity and credential/password management schemes. We identify common design…

密码学与安全 · 计算机科学 2020-08-11 Furkan Alaca , Paul C. van Oorschot

Modern web browsers have effectively become the new operating system for business applications, yet their security posture is often under-scrutinized. This paper presents a novel, comprehensive Browser Security Posture Analysis…

密码学与安全 · 计算机科学 2025-05-14 Avihay Cohen

Web3's decentralised infrastructure has upended the standardised approach to digital identity established by protocols like OpenID Connect. Web2 and Web3 currently operate in silos, with Web2 leveraging selective disclosure JSON web tokens…

密码学与安全 · 计算机科学 2025-01-24 Ben Biedermann , Matthew Scerri , Victoria Kozlova , Joshua Ellul

User authentication is one of the most important aspects for secure communication between services and end-users over the Internet. Service providers leverage Single-Sign On (SSO) to make it easier for their users to authenticate…

密码学与安全 · 计算机科学 2025-10-10 Kaustabh Barman , Fabian Piper , Sanjeet Raj Pandey , Axel Kuepper

Internet users are vulnerable to privacy attacks despite the use of encryption. Webpage fingerprinting, an attack that analyzes encrypted traffic, can identify the webpages visited by a user in a given website. Recent research works have…

密码学与安全 · 计算机科学 2022-05-31 Gargi Mitra , Prasanna Karthik Vairam , Sandip Saha , Nitin Chandrachoodan , V. Kamakoti
‹ 上一页 1 2 3 10 下一页 ›