Single Sign-on (SSO) protocols, which allow a website to authenticate its users via accounts registered with another website, are forming the basis of user identity management in contemporary websites. Given the critical role they are playing in safeguarding the privacy-sensitive web services and user data, SSO protocols deserve a rigorous formal verification. In this work, we provide a framework facilitating formal modeling of SSO protocols and analysis of their privacy property. Our framework incorporates a formal model of the web infrastructure (e.g., network and browsers), a set of attacker models (e.g., malicious IDP) and a formalization of the privacy property with respect to SSO protocols. Our analysis has identified a new type of at...
Millions of web users today employ their Facebook accounts to sign into more than one million relyin...
Single-Sign-On (SSO) protocols enable companies to estab-lish a federated environment in which clien...
OpenID and OAuth are open and lightweight web single sign-on (SSO) protocols that have been adopted ...
Web-based single sign-on (SSO) systems enable Web sites, so-called relying parties (RPs), to outsour...
Web-based single sign-on describes a class of protocols where a user signs into a web site with the ...
Web-based single sign-on describes a class of protocols where a user signs into a web site with the ...
Single Sign-On (SSO) is a solution where the authentication process is taken care of once by a third...
Many modern websites offer single sign-on (SSO) services, which allow the user to use an existing ac...
Single Sign-On (SSO) is a solution where the authentication process is taken care of once by a third...
Abstract—While security of cross-domain single sign-on is a thoroughly researched subject, the close...
Abstract—The web constitutes a complex infrastructure and, as demonstrated by numerous attacks, rigo...
Abstract—The web constitutes a complex infrastructure and, as demonstrated by numerous attacks, rigo...
OpenID and OAuth are open and lightweight web single sign-on (SSO) protocols that have been adopted ...
Abstract. Single Sign-On (SSO) systems simplify login procedures by using an an Identity Provider (I...
Single-Sign-On (SSO) protocols enable companies to establish a federated environment in which client...
Millions of web users today employ their Facebook accounts to sign into more than one million relyin...
Single-Sign-On (SSO) protocols enable companies to estab-lish a federated environment in which clien...
OpenID and OAuth are open and lightweight web single sign-on (SSO) protocols that have been adopted ...
Web-based single sign-on (SSO) systems enable Web sites, so-called relying parties (RPs), to outsour...
Web-based single sign-on describes a class of protocols where a user signs into a web site with the ...
Web-based single sign-on describes a class of protocols where a user signs into a web site with the ...
Single Sign-On (SSO) is a solution where the authentication process is taken care of once by a third...
Many modern websites offer single sign-on (SSO) services, which allow the user to use an existing ac...
Single Sign-On (SSO) is a solution where the authentication process is taken care of once by a third...
Abstract—While security of cross-domain single sign-on is a thoroughly researched subject, the close...
Abstract—The web constitutes a complex infrastructure and, as demonstrated by numerous attacks, rigo...
Abstract—The web constitutes a complex infrastructure and, as demonstrated by numerous attacks, rigo...
OpenID and OAuth are open and lightweight web single sign-on (SSO) protocols that have been adopted ...
Abstract. Single Sign-On (SSO) systems simplify login procedures by using an an Identity Provider (I...
Single-Sign-On (SSO) protocols enable companies to establish a federated environment in which client...
Millions of web users today employ their Facebook accounts to sign into more than one million relyin...
Single-Sign-On (SSO) protocols enable companies to estab-lish a federated environment in which clien...
OpenID and OAuth are open and lightweight web single sign-on (SSO) protocols that have been adopted ...