Biometrics and Electronic Signatures · 2008 · 16 citations · 2 references
EngineeringUsable SecurityInformation SecurityRelying-party-friendly ApproachDecentralized SecurityDigital Identity ManagementSecure ProtocolAuthentication ProtocolPublic Key InfrastructureInternet SecurityTransport Layer SecurityData PrivacyFederated Identity ManagementBlockchainWeb ServerData SecurityCryptographyIdentity FederationUser AgentsAuthentication Access Control
Federated Single-Sign-On using web browsers as User Agents becomes increasingly important. However, current proposals require substantial changes in the implementation of the Relying-Party, and concentrate on functionality rather than security against real-world attacks like Cross Site Scripting (XSS) and Pharming. We therefore propose a different approach based on Transport Layer Security (TLS), which is implemented in any web browser and web server, and which is immune against all currently known attacks.
2