Single sign-on to the web with an EMV card

被引:5
|
作者
Boyd, David J. [1 ]
机构
[1] Univ London, Informat Secur Grp, Egham TW20 0EX, Surrey, England
关键词
2FA; authentication; EMV; sign-on; SSO; web;
D O I
10.1109/CTS.2008.4543920
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Single sign-on has been on the wish-list of many information systems professionals since the early days of networked computers. Initially the challenge was to bridge a diverse range of proprietary systems but more recently the challenge has been to specify a system, particularly for the World Wide Web, that is: portable, suitable for universal deployment and sufficiently trustworthy for the participating entities. Some solutions have been developed but in general they rely on one party authenticating a user through a user id and password and the other participant organizations trusting that authentication. This paper proposes a framework for single sign-on that meets the mentioned criteria by using an EMV card for two-factor authentication, without the card making physical contact with the network connected device, and without exposing the keys and PIN that are used to protect financial transactions. The proposed framework also offers a basic form of single point of user registration that helps protect the cardholder's privacy from the service provider(s) and the framework could offer some non-repudiation properties for the authentication.
引用
下载
收藏
页码:112 / 120
页数:9
相关论文
共 50 条
  • [31] Grid single sign-on in CCLRC
    Jensen, Jens
    Spence, David
    Viljoen, Matthew
    PROCEEDINGS OF THE UK E-SCIENCE ALL HANDS MEETING 2006, 2006, : 273 - +
  • [32] Investigating Users' Perspectives of Web Single Sign-On: Conceptual Gaps and Acceptance Model
    Sun, San-Tsai
    Pospisil, Eric
    Muslukhov, Ildar
    Dindar, Nuray
    Hawkey, Kirstie
    Beznosov, Konstantin
    ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2013, 13 (01)
  • [33] A single sign-on protocol for distributed Web applications based on standard Internet mechanisms
    Gantner, Julian
    Geyer-Schulz, Andreas
    Thede, Anke
    E-BUSINESS AND TELECOMMUNICATION NETWORKS, 2006, : 167 - +
  • [34] Enabling Single Sign-On Authentication for Web Repositories using Domain Directory Services
    Kurian, Jayan C.
    Goh, Dion Hoe-Lian
    Htoo, Tint Hla Hla
    Wheeler, Lynn
    Hazel, Loh
    INTERNATIONAL SYMPOSIUM OF INFORMATION TECHNOLOGY 2008, VOLS 1-4, PROCEEDINGS: COGNITIVE INFORMATICS: BRIDGING NATURAL AND ARTIFICIAL KNOWLEDGE, 2008, : 48 - +
  • [35] MoSCAN: A Model-Based Vulnerability Scanner for Web Single Sign-On Services
    Wei, Hanlin
    Hassanshahi, Behnaz
    Bai, Guangdong
    Krishnan, Padmanabhan
    Vorobyov, Kostyantyn
    ISSTA '21: PROCEEDINGS OF THE 30TH ACM SIGSOFT INTERNATIONAL SYMPOSIUM ON SOFTWARE TESTING AND ANALYSIS, 2021, : 678 - 681
  • [36] Privacy-preserving Web single sign-on: Formal security analysis and design
    Schmitz, Guido
    IT-INFORMATION TECHNOLOGY, 2022, 64 (1-2): : 43 - 48
  • [37] Open Source in Web-Based Applications: A Case Study on Single Sign-On
    Ardagna, Claudio Agostino
    Frati, Fulvio
    Gianini, Gabriele
    INTERNATIONAL JOURNAL OF INFORMATION TECHNOLOGY AND WEB ENGINEERING, 2006, 1 (03) : 81 - 94
  • [38] Design and Realization of the component of Single Sign-on based on Web Services and Session Verification
    Zhang, Yi-lai
    Huang, Hua
    INFORMATION TECHNOLOGY APPLICATIONS IN INDUSTRY II, PTS 1-4, 2013, 411-414 : 481 - 485
  • [39] A Model of Unite-Authentication Single Sign-On Based on SAML underlying Web
    Wu Kaixing
    Yu Xiaolin
    ICIC 2009: SECOND INTERNATIONAL CONFERENCE ON INFORMATION AND COMPUTING SCIENCE, VOL 2, PROCEEDINGS: IMAGE ANALYSIS, INFORMATION AND SIGNAL PROCESSING, 2009, : 211 - 213
  • [40] Single Sign-On Under Quantum Cryptography
    Guiping Dai
    Yong Wang
    International Journal of Theoretical Physics, 2014, 53 : 188 - 193