Rethinking Single Sign-On: A Reliable and Privacy-Preserving Alternative with Verifiable Credentials

Rethinking Single Sign-On: A Reliable and Privacy-Preserving Alternative with Verifiable Credentials
复制标题

重新思考单点登录:具有可验证凭证的可靠且保护隐私的替代方案

DOI:
10.1145/3605760.3623767
复制
发表时间:
2023
期刊:
Proceedings of the 10th ACM Workshop on Moving Target Defense
影响因子:
--
通讯作者:
Xiao, Yang
Xiao, Yang
中科院分区:
--
文献类型:
--
作者:
Johnson, Athan D.;Alom, Ifteher;Xiao, Yang

文献摘要

参考文献

相似文献

单点登录(SSO)为Web域中的用户提供了便利,因为它可以授权用户使用身份提供商(IdP)的统一认证门户访问各种资源提供商(RP)。然而,单点登录也面临着安全问题,包括IdP单点故障和与身份链接相关的隐私。在本文中,我们提出了一个替代单点登录解决方案,称为VC-SSO的初始设计,以解决安全和隐私问题,同时保持单点登录的可用性。VC-SSO利用最近出现的分散式标识符(DID)和可验证凭证(VC)框架,因为用户仅需要向IdP认证一次以获得VC,然后可以从VC生成多个可验证呈现(VP)以访问不同的RP。这是基于这样的设计,即每个RP都与IdP建立了一个智能合约,指定服务协议和VP模式用于用户授权。我们希望所提出的VC-SSO设计标志着未来SSO系统的第一步,该系统在对抗条件下为用户提供强大的可靠性和隐私。
Single sign-on (SSO) has provided convenience to users in the web domain as it can authorize a user to access various resource providers (RPs) using the identity provider (IdP)'s unified authentication portal. However, SSO also faces security problems including IdP single-point failure and the privacy associated with identity linkage. In this paper, we present the initial design of an alternative SSO solution called VC-SSO to address the security and privacy problems while preserving SSO's usability. VC-SSO leverages the recently emerged decentralized identifier (DID) and verifiable credential (VC) framework in that a user only needs to authenticate with the IdP once to obtain a VC and then may generate multiple verifiable presentations (VPs) from the VC to access different RPs. This is based on the design that each RP has established a smart contract with the IdP specifying the service agreement and the VP schema for user authorization. We hope the proposed VC-SSO design marks the first step toward a future SSO system that provides strong reliability and privacy to users under adversarial conditions.
DOI: 10.1109/msp.2008.50
发表时间: 2008-03
影响因子: 1.9
作者:
Eve Maler;D. Reed
通讯作者: Eve Maler;D. Reed
SSI4Web:Web 的自我主权身份 (SSI) 框架
DOI: --
发表时间: 2022
期刊: International Congress on Blockchain and Applications
影响因子: --
作者:
M. Ferdous;Andrei Ionita;Wolfgang Prinz
通讯作者: Wolfgang Prinz
具有去中心化标识符和可验证凭证的基于分布式账本的身份验证
DOI: --
发表时间: 2020
期刊: Conference on Blockchain Research & Applications for Innovative Networks and Services
影响因子: --
作者:
Z. Lux;Dirk Thatmann;Sebastian Zickau;Felix Beierle
通讯作者: Felix Beierle
通过 SAML 集成将自我主权身份与联合且以用户为中心的身份连接起来
DOI: --
发表时间: 2021
期刊: International Symposium on Computers and Communications
影响因子: --
作者:
Hakan Yildiz;Christoph Ritter;Lan Thao Nguyen;Berit Frech;Maria Mora Martinez;Axel Küpper
通讯作者: Axel Küpper
DOI: --
发表时间: 2012
影响因子: 3.6
作者:
M. Urueña;Alfonso Muñoz;D. Larrabeiti
通讯作者: D. Larrabeiti