中文
相关论文

相关论文: Analysing the Security of Google's implementation …

200 篇论文

Millions of users routinely use Google to log in to websites supporting OAuth 2.0 or OpenID Connect; the security of OAuth 2.0 and OpenID Connect is therefore of critical importance. As revealed in previous studies, in practice RPs often…

密码学与安全 · 计算机科学 2019-01-28 Wanpeng Li , Chris J Mitchell , Thomas Chen

OAuth is the new de facto standard for delegating authorization in the web. An important limitation of OAuth is the fact that it was designed for authorization and not for authentication. The usage of OAuth for authentication thus leads to…

密码学与安全 · 计算机科学 2016-01-08 Vladislav Mladenov , Christian Mainka , Jörg Schwenk

Web-based single sign-on (SSO) services such as Google Sign-In and Log In with Paypal are based on the OpenID Connect protocol. This protocol enables so-called relying parties to delegate user authentication to so-called identity providers.…

密码学与安全 · 计算机科学 2019-01-31 Daniel Fett , Ralf Kuesters , Guido Schmitz

Many millions of users routinely use their Google, Facebook and Microsoft accounts to log in to websites supporting OAuth 2.0 and/or OpenID Connect-based single sign on. The security of OAuth 2.0 and OpenID Connect is therefore of critical…

密码学与安全 · 计算机科学 2018-01-25 Wanpeng Li , Chris J Mitchell , Thomas Chen

Single sign-on authentication systems such as OAuth 2.0 are widely used in web services. They allow users to use accounts registered with major identity providers such as Google and Facebook to login on multiple services (relying parties).…

密码学与安全 · 计算机科学 2021-03-04 Srivathsan G. Morkonda , Paul C. van Oorschot , Sonia Chiasson

The OAuth 2.0 protocol is one of the most widely deployed authorization/single sign-on (SSO) protocols and also serves as the foundation for the new SSO standard OpenID Connect. Despite the popularity of OAuth, so far analysis efforts were…

密码学与安全 · 计算机科学 2019-01-31 Daniel Fett , Ralf Kuesters , Guido Schmitz

Authentication and authorization are two key elements of a software application. In modern day, OAuth 2.0 framework and OpenID Connect protocol are widely adopted standards fulfilling these requirements. These protocols are implemented into…

密码学与安全 · 计算机科学 2018-08-21 Kavindu Dodanduwa , Ishara Kaluthanthri

OAuth 2.0 is a framework for authorization. Being a framework, OAuth 2.0 allows extensions to build on top of it. OpenID Connect is one such extension which adds authentication layer using identity details. OAuth 2.0 define several roles…

密码学与安全 · 计算机科学 2018-11-26 Kavindu Dodanduwa , Ishara Kaluthanthri

OpenID Connect (OIDC) is a widely used authentication standard for the Web. In this work, we define a new Identity Certification Token (ICT) for OIDC. An ICT can be thought of as a JSON-based, short-lived user certificate for end-to-end…

密码学与安全 · 计算机科学 2024-06-13 Jonas Primbs , Michael Menth

Single sign-on (SSO) systems, such as OpenID and OAuth, allow web sites, so-called relying parties (RPs), to delegate user authentication to identity providers (IdPs), such as Facebook or Google. These systems are very popular, as they…

密码学与安全 · 计算机科学 2015-08-10 Daniel Fett , Ralf Kuesters , Guido Schmitz

Single Sign-On (SSO) systems simplify login procedures by using an an Identity Provider (IdP) to issue authentication tokens which can be consumed by Service Providers (SPs). Traditionally, IdPs are modeled as trusted third parties. This is…

密码学与安全 · 计算机科学 2014-12-05 Christian Mainka , Vladislav Mladenov , Jörg Schwenk

OpenID Connect (OIDC) enables a user with commercial-off-the-shelf browsers to log into multiple websites, called relying parties (RPs), by her username and credential set up in another trusted web system, called the identity provider…

密码学与安全 · 计算机科学 2025-07-02 Jingqiang Lin , Baitao Zhang , Wei Wang , Quanwei Cai , Jiwu Jing , Huiyang He

Web3's decentralised infrastructure has upended the standardised approach to digital identity established by protocols like OpenID Connect. Web2 and Web3 currently operate in silos, with Web2 leveraging selective disclosure JSON web tokens…

密码学与安全 · 计算机科学 2025-01-24 Ben Biedermann , Matthew Scerri , Victoria Kozlova , Joshua Ellul

Forced by regulations and industry demand, banks worldwide are working to open their customers' online banking accounts to third-party services via web-based APIs. By using these so-called Open Banking APIs, third-party companies, such as…

密码学与安全 · 计算机科学 2019-02-01 Daniel Fett , Pedram Hosseyni , Ralf Kuesters

Social authentication has been suggested as a usable authentication ceremony to replace manual key authentication in messaging applications. Using social authentication, chat partners authenticate their peers using digital identities…

密码学与安全 · 计算机科学 2024-02-06 Felix Linker , David Basin

OpenID is a standard decentralized initiative aimed at allowing Internet users to use the same personal account to access different services. Since it does not rely on any central authority, it is hard for such users or other entities to…

密码学与安全 · 计算机科学 2014-06-02 Ginés Dólera Tormo , Félix Gómez Mármol , Gregorio Martínez Pérez

Googles A2A protocol provides a secure communication framework for AI agents but demonstrates critical limitations when handling highly sensitive information such as payment credentials and identity documents. These gaps increase the risk…

密码学与安全 · 计算机科学 2025-09-01 Yedidel Louck , Ariel Stulman , Amit Dvir

Federated identity management enables users to access multiple systems using a single login credential. However, to achieve this a complex privacy compromising authentication has to occur between the user, relying party (RP) (e.g., a…

密码学与安全 · 计算机科学 2019-06-27 Peter Mell , Jim Dray , James Shook

The number of login options on web sites has increased since the introduction of web single sign-on (SSO) protocols. Web SSO services allow users to grant web sites or relying parties (RPs) access to their personal profile information from…

密码学与安全 · 计算机科学 2024-12-23 Srivathsan G. Morkonda , Sonia Chiasson , Paul C. van Oorschot

Self-Sovereign Identity (SSI), as a new and promising identity management paradigm, needs mechanisms that can ease a gradual transition of existing services and developers towards it. Systems that bridge the gap between SSI and established…

密码学与安全 · 计算机科学 2024-01-19 Felix Hoops , Florian Matthes
‹ 上一页 1 2 3 10 下一页 ›