ROSTAM: A passwordless web single sign-on solution mitigating server breaches and integrating credential manager and federated identity systems

被引:1
|
作者
Mahnamfar, Amin [1 ]
Bicakci, Kemal [1 ,2 ,3 ]
Uzunay, Yusuf [3 ]
机构
[1] Istanbul Tech Univ, Informat Inst, TR-34467 Istanbul, Turkiye
[2] Istanbul Tech Univ, Comp Engn Dept, TR-34467 Istanbul, Turkiye
[3] Securify Informat Technol & Secur Training Consult, TR-06378 Ankara, Turkiye
关键词
Single sign -on; SSO; Password managers; Usable security; Master password; Master key; Passwordless; User authentication;
D O I
10.1016/j.cose.2024.103739
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The challenge of achieving passwordless user authentication is real given the prevalence of web applications that keep asking passwords. Complicating this issue further, in an enterprise environment, a single sign-on (SSO) service is often maintained but not all applications can be integrated with it. We envision a passwordless future which provides a frictionless and trustworthy online experience for users by integrating credential management and federated identity systems. In this regard, our implementation ROSTAM offers a dashboard that presents all applications the user can access with a single click after a passwordless SSO. The security of web passwords on the credential manager is ensured with a Master Key, rather than a Master Password, so that encrypted passwords can remain secure even if stolen from the server. We propose and implement novel techniques for synchronization (pairing) and recovery of this Master Key. We compare our solution to previous work using different evaluation frameworks, demonstrating that our hybrid solution combines the benefits of credential management and federated identity systems.
引用
收藏
页数:14
相关论文
empty
未找到相关数据