{"title":"A Single Sign on based secure remote user authentication scheme for Multi-Server Environments","authors":"S. Binu, M. Misbahuddin, P. Raj","doi":"10.1109/ICCCT2.2014.7066715","DOIUrl":null,"url":null,"abstract":"A Multi-Server Architecture comprises of a server environment having many different servers which provides the user the flexibility of accessing resources from multiple Service Providing Servers using the same credential. The primary objective of a Multi Server Environment (MSE) is to provide services of different Service Providers (SPs) without repeating registration at each SP server, and to get a unique single credential for all the servers in MSE. However, the conventional MSEs, proposed by various researchers, proposes the individual authentication service by each SP on their respective server using the credential issued by the Registration Authority of MSE. The mechanism requires the user to access each SP by keying the same credentials for every SP separately. Single Sign On (SSO) is an authentication mechanism that enables a user to sign-on once and access the services of various SPs in the same session. SAML is generally used as a Single Sign-On protocol. This work analyzes the smart card based authentication scheme for Multi-Server Environment proposed by Li et al.'s and discuss various security attacks on the said scheme. The paper also proposes a Secure Dynamic-ID based scheme using smart cards or crypto cards which do not require a verifier table and implements Single Sign On feature using SAML protocol, thus allowing the user to enjoy all the features of an MSE along with SSO.","PeriodicalId":6860,"journal":{"name":"2021 RIVF International Conference on Computing and Communication Technologies (RIVF)","volume":"7 1","pages":"1-6"},"PeriodicalIF":0.0000,"publicationDate":"2014-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 RIVF International Conference on Computing and Communication Technologies (RIVF)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCCT2.2014.7066715","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5
Abstract
A Multi-Server Architecture comprises of a server environment having many different servers which provides the user the flexibility of accessing resources from multiple Service Providing Servers using the same credential. The primary objective of a Multi Server Environment (MSE) is to provide services of different Service Providers (SPs) without repeating registration at each SP server, and to get a unique single credential for all the servers in MSE. However, the conventional MSEs, proposed by various researchers, proposes the individual authentication service by each SP on their respective server using the credential issued by the Registration Authority of MSE. The mechanism requires the user to access each SP by keying the same credentials for every SP separately. Single Sign On (SSO) is an authentication mechanism that enables a user to sign-on once and access the services of various SPs in the same session. SAML is generally used as a Single Sign-On protocol. This work analyzes the smart card based authentication scheme for Multi-Server Environment proposed by Li et al.'s and discuss various security attacks on the said scheme. The paper also proposes a Secure Dynamic-ID based scheme using smart cards or crypto cards which do not require a verifier table and implements Single Sign On feature using SAML protocol, thus allowing the user to enjoy all the features of an MSE along with SSO.
多服务器体系结构由具有许多不同服务器的服务器环境组成,这些服务器为用户提供了使用相同凭据访问来自多个服务提供服务器的资源的灵活性。多服务器环境(MSE)的主要目标是提供不同服务提供者(SP)的服务,而无需在每个SP服务器上重复注册,并为MSE中的所有服务器获得唯一的单个凭据。然而,由各种研究人员提出的传统MSE,由每个SP在各自的服务器上使用MSE的注册机构颁发的凭据提出单独的身份验证服务。该机制要求用户通过为每个SP分别键入相同的凭据来访问每个SP。单点登录(Single Sign On, SSO)是一种允许用户一次登录并在同一会话中访问多个服务提供商的服务的认证机制。SAML通常用作单点登录协议。本文分析了Li等人提出的基于智能卡的多服务器环境认证方案,并讨论了针对该方案的各种安全攻击。本文还提出了一种安全的基于动态id的方案,该方案使用智能卡或加密卡,不需要验证表,并使用SAML协议实现单点登录功能,从而允许用户在单点登录的同时享受MSE的所有功能。