首页> 外文会议>IEEE International Conference on Advanced Computing >Hybrid Single Sign-On Protocol for Lightweight Devices
【24h】

Hybrid Single Sign-On Protocol for Lightweight Devices

机译:轻量级设备的混合单点登录协议

获取原文

摘要

As the dependency on Internet is increasing, the service providers are launching numerous web applications to facilitate the users. Due to threat of unauthorized access they want to identify their users accurately. In the same way, leakage of sensitive information makes clients aware enough to make sure whom they are dealing with. This leads to the requirement of a Centralized Authentication System(CAS). The involvement of CAS introduces the single sign on capability at client side. Once the individual proves his identity to the CAS, it will be assured to all those services that trust on CAS. There are several existing solutions like Kerberos and SAML. This paper introduces a single sign-on protocol which combines the protocol architecture of Kerberos with the functionality of SAML. Finding the deficits in the SAML architecture we try to improve it by adapting strong protocol architecture. As a proof of concept, we study the formal analysis of the proposed security protocol through different tools like CASPER and SCYTHER.
机译:随着对Internet的依赖性增加,服务提供商正在启动许多Web应用程序以便利用户。由于存在未经授权访问的威胁,他们希望准确识别其用户。以同样的方式,敏感信息的泄漏使客户足够了解自己,以确保他们正在与谁打交道。这导致了对集中式身份验证系统(CAS)的要求。 CAS的参与在客户端引入了单点登录功能。一旦个人向CAS证明了自己的身份,就会向所有信任CAS的服务提供保证。有几种现有的解决方案,例如Kerberos和SAML。本文介绍了一种单点登录协议,该协议将Kerberos的协议体系结构与SAML的功能相结合。在发现SAML体系结构中的不足之处时,我们尝试通过采用强大的协议体系结构来改善它。作为概念的证明,我们通过不同的工具(例如,CASPER和SCYTHER)研究了提议的安全协议的形式分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号