中文
相关论文

相关论文: SPRESSO: A Secure, Privacy-Respecting Single Sign-…

200 篇论文

Single sign-on (SSO) allows a user to maintain only the credential for an identity provider (IdP) to log into multiple relying parties (RPs). However, SSO introduces privacy threats, as (a) a curious IdP could track a user's all visits to…

密码学与安全 · 计算机科学 2025-03-27 Chengqian Guo , Jingqiang Lin , Quanwei Cai , Wei Wang , Wentian Zhu , Jiwu Jing , Qiongxiao Wang , Bin Zhao , Fengjun Li

The number of login options on web sites has increased since the introduction of web single sign-on (SSO) protocols. Web SSO services allow users to grant web sites or relying parties (RPs) access to their personal profile information from…

密码学与安全 · 计算机科学 2024-12-23 Srivathsan G. Morkonda , Sonia Chiasson , Paul C. van Oorschot

BrowserID is a complex, real-world Single Sign-On (SSO) System for web applications recently developed by Mozilla. It employs new HTML5 features (such as web messaging and web storage) and cryptographic assertions to provide decentralized…

密码学与安全 · 计算机科学 2019-01-31 Daniel Fett , Ralf Kuesters , Guido Schmitz

Web-based single sign-on (SSO) services such as Google Sign-In and Log In with Paypal are based on the OpenID Connect protocol. This protocol enables so-called relying parties to delegate user authentication to so-called identity providers.…

密码学与安全 · 计算机科学 2019-01-31 Daniel Fett , Ralf Kuesters , Guido Schmitz

Single sign-on (SSO) allows users to authenticate to third-party applications through a central identity provider. Despite their wide adoption, deployed SSO systems suffer from privacy problems such as user tracking by the identity…

密码学与安全 · 计算机科学 2023-12-15 Rongwu Xu , Sen Yang , Fan Zhang , Zhixuan Fang

User authentication is one of the most important aspects for secure communication between services and end-users over the Internet. Service providers leverage Single-Sign On (SSO) to make it easier for their users to authenticate…

密码学与安全 · 计算机科学 2025-10-10 Kaustabh Barman , Fabian Piper , Sanjeet Raj Pandey , Axel Kuepper

Single Sign-On (SSO) systems simplify login procedures by using an an Identity Provider (IdP) to issue authentication tokens which can be consumed by Service Providers (SPs). Traditionally, IdPs are modeled as trusted third parties. This is…

密码学与安全 · 计算机科学 2014-12-05 Christian Mainka , Vladislav Mladenov , Jörg Schwenk

OpenID Connect (OIDC) enables a user with commercial-off-the-shelf browsers to log into multiple websites, called relying parties (RPs), by her username and credential set up in another trusted web system, called the identity provider…

密码学与安全 · 计算机科学 2025-07-02 Jingqiang Lin , Baitao Zhang , Wei Wang , Quanwei Cai , Jiwu Jing , Huiyang He

We introduce EL PASSO, a privacy-preserving, asynchronous Single Sign-On (SSO) system. It enables personal authentication while protecting users' privacy against both identity providers and relying parties, and allows selective attribute…

密码学与安全 · 计算机科学 2021-06-15 Zhiyi Zhang , Michał Król , Alberto Sonnino , Lixia Zhang , Etienne Rivière

In the digital age, individuals increasingly maintain active presences across multiple platforms ranging from social media and messaging applications to professional and communication tools. However, the current model for managing user…

密码学与安全 · 计算机科学 2025-07-10 Paritosh Ranjan , Surajit Majumder , Prodip Roy

An anonymous Single Sign-On (ASSO) scheme allows users to access multiple services anonymously using one credential. We propose a new ASSO scheme, where users can access services anonymously through the use of anonymous credentials and…

密码学与安全 · 计算机科学 2019-04-12 Jinguang Han , Liqun Chen , Steve Schneider , Helen Treharne , Stephan Wesemeyer , Nick Wils

We perform a comprehensive analysis and comparison of 14 web single sign-on (SSO) systems proposed and/or deployed over the last decade, including federated identity and credential/password management schemes. We identify common design…

密码学与安全 · 计算机科学 2020-08-11 Furkan Alaca , Paul C. van Oorschot

Approved client-server authentication mechanisms are described for the IVOA single-sign-on profile: No Authentication; HTTP Basic Authentication; TLS with passwords; TLS with client certificates; Cookies; Open Authentication; Security…

天体物理仪器与方法 · 物理学 2019-06-05 Giuliano Taffoni , André Schaaff , Guy Rixon , Brian Major

Single sign-on authentication systems such as OAuth 2.0 are widely used in web services. They allow users to use accounts registered with major identity providers such as Google and Facebook to login on multiple services (relying parties).…

密码学与安全 · 计算机科学 2021-03-04 Srivathsan G. Morkonda , Paul C. van Oorschot , Sonia Chiasson

Passwordless authentication has revolutionized the way we authenticate across various websites and services. FIDO2 Passkeys, is one of the most-widely adopted standards of passwordless authentication that promises phishing-resistance.…

密码学与安全 · 计算机科学 2025-12-29 Aditya Mitra , Sibi Chakkaravarthy Sethuraman

Anonymous Single-Sign-On authentication schemes have been proposed to allow users to access a service protected by a verifier without revealing their identity which has become more important due to the introduction of strong privacy…

密码学与安全 · 计算机科学 2018-04-20 Jinguang Han , Liqun Chen , Steve Schneider , Helen Treharne , Stephan Wesemeyer

Web users are increasingly presented with multiple login options, including password-based login and common web single sign-on (SSO) login options such as "Login with Google" and "Login with Facebook". There has been little focus in…

人机交互 · 计算机科学 2023-12-29 Srivathsan G. Morkonda , Sonia Chiasson , Paul C. van Oorschot

Many millions of users routinely use their Google accounts to log in to relying party (RP) websites supporting the Google OpenID Connect service. OpenID Connect, a newly standardised single-sign-on protocol, builds an identity layer on top…

密码学与安全 · 计算机科学 2015-08-10 Wanpeng Li , Chris J Mitchell

OAuth 2.0 is a popular authorization framework that allows third-party clients such as websites and mobile apps to request limited access to a user's account on another application. The specification classifies clients into different types…

密码学与安全 · 计算机科学 2023-08-03 Jaimandeep Singh , Naveen Kumar Chaudhary

Single Sign-On (SSO) shifts the crucial authentication process on a website to to the underlying SSO protocols and their correct implementation. To strengthen SSO security, organizations, such as IETF and W3C, maintain advisories to address…

密码学与安全 · 计算机科学 2023-02-03 Maximilian Westers , Tobias Wich , Louis Jannett , Vladislav Mladenov , Christian Mainka , Andreas Mayer
‹ 上一页 1 2 3 10 下一页 ›