Yayın:
ROSTAM: A passwordless web single sign-on solution mitigating server breaches and integrating credential manager and federated identity systems

dc.contributor.authorMahnamfar, Amin
dc.contributor.authorBicakci, Kemal
dc.contributor.authorUzunay, Yusuf
dc.contributor.ituauthorBıçakcı, Kemal
dc.date.accessioned2026-01-26T07:26:38Z
dc.date.issued2023-01-01
dc.description.abstractThe challenge of achieving passwordless user authentication is real given the prevalence of web applications that keep asking passwords. Complicating this issue further, in an enterprise environment, a single sign-on (SSO) service is often maintained but not all applications can be integrated with it. We envision a passwordless future which provides a frictionless and trustworthy online experience for users by integrating credential management and federated identity systems. In this regard, our implementation ROSTAM offers a dashboard that presents all applications the user can access with a single click after a passwordless SSO. The security of web passwords on the credential manager is ensured with a Master Key, rather than a Master Password, so that encrypted passwords can remain secure even if stolen from the server. We propose and implement novel techniques for synchronization (pairing) and recovery of this Master Key. We compare our solution to previous work using different evaluation frameworks, demonstrating that our hybrid solution combines the benefits of credential management and federated identity systems.
dc.description.abstract38 pages
dc.description.urihttps://doi.org/10.1016/j.cose.2024.103739
dc.description.urihttps://doi.org/10.2139/ssrn.4606664
dc.description.urihttps://dx.doi.org/10.48550/arxiv.2310.05222
dc.description.urihttp://arxiv.org/abs/2310.05222
dc.description.urihttps://doi.org/10.48550/arXiv.2310.05222
dc.identifier.doi10.1016/j.cose.2024.103739
dc.identifier.issn0167-4048
dc.identifier.openairedoi_dedup___::f564b0f56b1e4fa0d161406634a2d268
dc.identifier.orcid0000-0003-1978-2498
dc.identifier.orcid0000-0002-2378-8027
dc.identifier.startpage103739
dc.identifier.urihttps://hdl.handle.net/11527/63558
dc.identifier.volume139
dc.language.isoeng
dc.publisherElsevier BV
dc.relation.ispartofComputers & Security
dc.rightsOPEN
dc.subjectFOS: Computer and information sciences
dc.subjectComputer Science - Cryptography and Security
dc.subjectCryptography and Security (cs.CR)
dc.titleROSTAM: A passwordless web single sign-on solution mitigating server breaches and integrating credential manager and federated identity systems
dc.typeArticle
dspace.entity.typePublication
person.identifier.orcid0000-0002-2378-8027

Dosyalar

Koleksiyonlar