Single sign-on to the web with an EMV card

被引:5
|
作者
Boyd, David J. [1 ]
机构
[1] Univ London, Informat Secur Grp, Egham TW20 0EX, Surrey, England
关键词
2FA; authentication; EMV; sign-on; SSO; web;
D O I
10.1109/CTS.2008.4543920
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Single sign-on has been on the wish-list of many information systems professionals since the early days of networked computers. Initially the challenge was to bridge a diverse range of proprietary systems but more recently the challenge has been to specify a system, particularly for the World Wide Web, that is: portable, suitable for universal deployment and sufficiently trustworthy for the participating entities. Some solutions have been developed but in general they rely on one party authenticating a user through a user id and password and the other participant organizations trusting that authentication. This paper proposes a framework for single sign-on that meets the mentioned criteria by using an EMV card for two-factor authentication, without the card making physical contact with the network connected device, and without exposing the keys and PIN that are used to protect financial transactions. The proposed framework also offers a basic form of single point of user registration that helps protect the cardholder's privacy from the service provider(s) and the framework could offer some non-repudiation properties for the authentication.
引用
收藏
页码:112 / 120
页数:9
相关论文
共 50 条
  • [1] Using EMV cards for single sign-on
    Pashalidis, A
    Mitchell, CJ
    [J]. PUBLIC KEY INFRASTRUCTURE, PROCEEDINGS, 2004, 3093 : 205 - 217
  • [2] CHARACTERIZATION OF WEB SINGLE SIGN-ON PROTOCOLS
    Beltran, Victoria
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2016, 54 : 24 - 30
  • [3] Single sign-on protocol for web services
    Zheng, Dong-Xi
    Tang, Shao-Hua
    Li, Shao-Fa
    [J]. Huanan Ligong Daxue Xuebao/Journal of South China University of Technology (Natural Science), 2005, 33 (02): : 65 - 69
  • [4] Design of a scalable single sign-on for web service
    Huang, He
    Liu, Qingwen
    Zhao, Liang
    Liu, Fengchen
    [J]. 2007 INTERNATIONAL SYMPOSIUM ON COMPUTER SCIENCE & TECHNOLOGY, PROCEEDINGS, 2007, : 384 - 388
  • [5] Single Sign-On Assistant: An Authentication Broker for Web Applications
    Zhu, Fei
    Diao, Hongjun
    [J]. THIRD INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING: WKDD 2010, PROCEEDINGS, 2010, : 146 - 149
  • [6] Web services single sign-on protocol and formal analysis on it
    Zheng, DX
    Tang, SH
    Li, SF
    [J]. JOURNAL OF CIRCUITS SYSTEMS AND COMPUTERS, 2005, 14 (05) : 923 - 930
  • [7] Using Smart Card to Achieve a Single Sign-on for Multiple Cloud Services
    Hwang, Min-Shiang
    Sun, Tsuei-Hung
    [J]. IETE TECHNICAL REVIEW, 2013, 30 (05) : 410 - 416
  • [8] Comparative Analysis and Framework Evaluating Web Single Sign-on Systems
    Alaca, Furkan
    Van Oorschot, Paul C.
    [J]. ACM COMPUTING SURVEYS, 2020, 53 (05)
  • [9] Single Sign-On Taxonomy
    Ivanova, Asya I.
    Vodanovich, Shahper
    [J]. 2017 IEEE 21ST INTERNATIONAL CONFERENCE ON COMPUTER SUPPORTED COOPERATIVE WORK IN DESIGN (CSCWD), 2017, : 151 - 155
  • [10] Single sign-on for Java Web Start applications using MyProxy
    National Center for Supercomputing Applications, 1205 W. Clark St., Urbana, IL 61801, United States
    [J]. ACM SIGSAC, 1600, 95-101 (2006):