Impostor: A single sign-on system for use from untrusted devices.

被引:0
|
作者
Pashalidis, A [1 ]
Mitchell, CJ [1 ]
机构
[1] Univ London Royal Holloway & Bedford New Coll, Informat Secur Grp, Egham TW20 0EX, Surrey, England
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
At present, network users have to manage a set of authentication credentials (usually a username/password pair) for every service with which they are registered. Single Sign-On (SSO) has been proposed as a solution to the usability, security and management implications of this situation. Under SSO, users need to manage only one set of authentication credentials in order to log into the services they subsequently use. This paper presents the design of an SSO system that is based on a trusted proxy, and that is suitable for use from an untrusted network access device. Unlike existing proxy-based SSO schemes, which require an infrastructure to be in place between the proxy and the service providers, the one presented here does not. An open-source implementation of the scheme, called 'Impostor', is also described. The prototype is implemented as an HTTP proxy, resulting in a system that works with common web browsers.
引用
收藏
页码:2191 / 2195
页数:5
相关论文
共 50 条
  • [1] Scalable single sign-on system
    Huang, He
    Shan, Zhiguang
    Huang, Dongquan
    Journal of Southeast University (English Edition), 2007, 23 (03) : 465 - 468
  • [2] Single sign-on and the system administrator
    Grubb, MF
    Carter, R
    PROCEEDINGS OF THE TWELFTH SYSTEMS ADMINISTRATION CONFERENCE (LISA XII), 1998, : 63 - 86
  • [3] Hybrid Single Sign-On Protocol For Lightweight Devices
    Sharma, Payal
    Sihag, Vikas Kumar
    2016 IEEE 6TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (IACC), 2016, : 679 - 684
  • [4] Traffic Evaluation of a Claim-based Single Sign-On System with Focus on Mobile Devices
    Khalil, Mateusz
    Rebahi, Yacine
    Hohberg, Simon
    Lorenz, Pascal
    EIGHTH ADVANCED INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS (AICT 2012), 2012, : 144 - 149
  • [5] A user-centric federated single sign-on system
    Suriadi, Suriadi
    Foo, Ernest
    Josang, Audun
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2009, 32 (02) : 388 - 401
  • [6] SAML-Based Single Sign-On for Legacy System
    Nie, Fengming
    Xu, Feng
    Qi, Rongzhi
    2012 IEEE INTERNATIONAL CONFERENCE ON AUTOMATION AND LOGISTICS (ICAL), 2012, : 470 - 473
  • [7] A User-centric Federated Single Sign-on System
    Suriadi, Suriadi
    Foo, Ernest
    Josang, Audun
    2007 IFIP INTERNATIONAL CONFERENCE ON NETWORK AND PARALLEL COMPUTING WORKSHOPS, PROCEEDINGS, 2007, : 99 - 106
  • [8] An implement of single sign-on system based on cookie mechanism
    Cheng Xuexian
    Cheng Chuanhui
    Zhao Pu
    Advanced Computer Technology, New Education, Proceedings, 2007, : 874 - 876
  • [9] A Security Research on Single Sign-On System Based on CAS
    Zhang Xiao-yin
    Chen Guo-sheng
    2011 INTERNATIONAL CONFERENCE ON COMPUTER APPLICATION AND EDUCATION TECHNOLOGY (ICCAET 2011), 2011, : 209 - 212
  • [10] A Performant and Secure Single Sign-On System Using Microservices
    Moghaddam, Mahyar T.
    Pedersen, Andreas Edal
    Bolding, William Walter Lillebroe
    Worm, Torben
    38TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2023, 2023, : 1516 - 1519