Michitomo Morii, Hiroki Tanioka, K. Ohira, M. Sano, Yosuke Seki, Kenji Matsuura, T. Ueta
{"title":"Research on Integrated Authentication Using Passwordless Authentication Method","authors":"Michitomo Morii, Hiroki Tanioka, K. Ohira, M. Sano, Yosuke Seki, Kenji Matsuura, T. Ueta","doi":"10.1109/COMPSAC.2017.198","DOIUrl":null,"url":null,"abstract":"Currently, authentication methods using ID and password are widely used and fulfilled central roles in various information systems and services. Our university also uses ID and password for authentication of most services. However, passwords have various problems such as reuse, phishing and leakage. This research is a practical experiment in order to implement an integrated authentication system without password. Shibboleth is introduced to our university, providing capabilities of web single sign-on and attribute exchange framework for organizational services. The Fast IDentity Online (FIDO) is adopted into Shibboleth as an external authentication, to realize passwordless authentication. Furthermore, we held a feasibility test of an integrated authentication system without password, and considered problems of the passwordless authentication method using FIDO.","PeriodicalId":6556,"journal":{"name":"2017 IEEE 41st Annual Computer Software and Applications Conference (COMPSAC)","volume":"95 1","pages":"682-685"},"PeriodicalIF":0.0000,"publicationDate":"2017-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"13","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 IEEE 41st Annual Computer Software and Applications Conference (COMPSAC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/COMPSAC.2017.198","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 13
Abstract
Currently, authentication methods using ID and password are widely used and fulfilled central roles in various information systems and services. Our university also uses ID and password for authentication of most services. However, passwords have various problems such as reuse, phishing and leakage. This research is a practical experiment in order to implement an integrated authentication system without password. Shibboleth is introduced to our university, providing capabilities of web single sign-on and attribute exchange framework for organizational services. The Fast IDentity Online (FIDO) is adopted into Shibboleth as an external authentication, to realize passwordless authentication. Furthermore, we held a feasibility test of an integrated authentication system without password, and considered problems of the passwordless authentication method using FIDO.