Smart OpenID: A smart card based OpenID protocol

13Citations
Citations of this article
14Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

OpenID is a lightweight, easy to implement and deploy approach to Single Sign-On (SSO) and Identity Management (IdM), and has great potential for large scale user adoption especially for mobile applications. At the same time, Mobile Network Operators are increasingly interested in leveraging their existing infrastructure and assets for SSO and IdM. In this paper, we present the concept of Smart OpenID, an enhancement to OpenID which moves part of the OpenID authentication server functionality to the smart card of the user's device. This seamless, OpenID-conformant protocol allows for scaling security properties, and generally improves the security of OpenID by avoiding the need to send user credentials over the Internet and thus avoid phishing attacks. We also describe our implementation of the Smart OpenID protocol based on an Android phone, which interacts with OpenID-enabled web services. © 2012 IFIP International Federation for Information Processing.

Cite

CITATION STYLE

APA

Leicher, A., Schmidt, A. U., & Shah, Y. (2012). Smart OpenID: A smart card based OpenID protocol. In IFIP Advances in Information and Communication Technology (Vol. 376 AICT, pp. 75–86). https://doi.org/10.1007/978-3-642-30436-1_7

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free