A Novel Distributed Single Sign-On Scheme with Dynamically Changed Threshold Value

被引:0
|
作者
Zhong, Shangping [1 ]
Liao, Xiangwen [1 ]
Zhang, Xue [1 ]
Lin, Jingqu [1 ]
机构
[1] Fuzhou Univ, Dept Comp Sci & Technol, Fuzhou 350002, Peoples R China
关键词
Single Sign-On scheme; threshold-based; dynamically changed threshold value; conspiracy-impersonation attack; DctSSO;
D O I
10.1109/IAS.2009.194
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
A Single Sign-On (SSO) system allow single authentication for multiple services. It is a potential solution to the implications of security, credentials management, et M. Recently, several works have used the threshold-based secret sharing scheme to create a distributed SSO service. All these works setup the threshold parameters first in the system initiation. But in some real-world applications, the threshold value should be dynamically changed in the authentication phase. In this paper, we present a novel threshold-based distributed Single Sign-On scheme with a dynamically changed threshold value(DctSSO). In DctSSO, two different degree secret polynomials are constructed. Each authentication server has two kinds of secret keys: keys for initiation shares and keys for authentication shares. Through the simply XOR operation, authentication shares keys can be delivered securely. DctSSO is not only as good as Threspassport on the aspects of security, portability, intrusion and fault tolerance, scalability, reliability, and availability, but also it offers two significant advantages over ThresPassport : it has the dynamically, securely and availably changed threshold Value in the authentication phase, and it can prevent conspiracy-impersonation attacks.
引用
收藏
页码:563 / 566
页数:4
相关论文
共 38 条
  • [1] Design on a Single Sign-On Scheme
    Lei, Wen
    Liang, Xingjian
    Zhang, Hong
    [J]. ADVANCES IN SCIENCE AND ENGINEERING, PTS 1 AND 2, 2011, 40-41 : 531 - 536
  • [2] An Improved Scheme of Single Sign-on Protocol
    Jian, Yang
    [J]. FIFTH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY, VOL 1, PROCEEDINGS, 2009, : 495 - 498
  • [3] ThresPassport - A distributed single sign-on service
    Chen, TR
    Zhu, BB
    Li, SP
    Cheng, XQ
    [J]. ADVANCES IN INTELLIGENT COMPUTING, PT 2, PROCEEDINGS, 2005, 3645 : 771 - 780
  • [4] Clinical impact and value of workstation single sign-on
    Gellert, George A.
    Crouch, John F.
    Gibson, Lynn A.
    Conklin, George S.
    Webster, S. Luke
    Gillean, John A.
    [J]. INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2017, 101 : 131 - 136
  • [5] A Secure Single Sign-On Mechanism for Distributed Computer Networks
    Chang, Chin-Chen
    Lee, Chia-Yin
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2012, 59 (01) : 629 - 637
  • [6] Single Sign-On Integration in a Distributed Enterprise Service Bus
    Sliman, Layth
    Badr, Youakim
    Biennier, Frederique
    Salatge, Nicolas
    Nakao, Zensho
    [J]. 2009 INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE SECURITY, 2009, : 56 - +
  • [7] Practical Single Sign-on Mechanism for Distributed Computer Networks
    Huang, Li
    Tang, Xinlai
    Liu, Hao
    Xiao, Da
    [J]. AD HOC & SENSOR WIRELESS NETWORKS, 2016, 31 (1-4) : 131 - 149
  • [8] UniWare: A novel security Single Sign-On model
    Liu, Shuang
    Zhao, Zheng
    Xue, Guixiang
    Shi, Wei
    [J]. 2008 PROCEEDINGS OF INFORMATION TECHNOLOGY AND ENVIRONMENTAL SYSTEM SCIENCES: ITESS 2008, VOL 4, 2008, : 418 - 421
  • [9] Toward A Secure Single Sign-On Mechanism for Distributed Computer Networks
    Lee, Cheng-Chi
    Lai, Yan-Ming
    [J]. COMPUTER JOURNAL, 2015, 58 (04): : 934 - 943
  • [10] Preventing single sign-on impersonation attacks with a keyless signature scheme
    Alabrah, Amerah
    Bassiouni, Mostafa
    [J]. 2017 10TH IFIP WIRELESS AND MOBILE NETWORKING CONFERENCE (WMNC 2017), 2017,