亲爱的研友该休息了!由于当前在线用户较少,发布求助请尽量完整的填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!身体可是革命的本钱,早点休息,好梦!

PrivSSO: Practical Single-sign-on Authentication against Subscription/Access Pattern Leakage

计算机科学 单一登录 泄漏(经济) 认证(法律) 计算机安全 计算机网络 宏观经济学 经济
作者
Ge Gao,Yuan Zhang,Yaqing Song,Shiyu Li
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:19: 5075-5089 被引量:1
标识
DOI:10.1109/tifs.2024.3392533
摘要

Single-sign-on (SSO) authentication employs an identity provider (IdP) to provide users with an efficient way to authenticate themselves with different service providers and has been widely applied in digital systems. However, existing SSO authentication schemes suffer from critical issues in terms of security and privacy. Regarding security, most SSO authentication schemes achieve a high convenience at the expense of security and are thereby susceptible to various attacks. Regarding privacy, most existing schemes fail to protect users' subscription pattern and access pattern against adversaries who can easily extract users' sensitive information from their authentications and launch subsequent attacks for profits. In this paper, we develop a practical SSO authentication system, dubbed PrivSSO, with the protection of users' subscription pattern and access pattern. To balance the trade-off between security and convenience, the key technique is a secure "hybrid" key-based authentication mechanism: a long-term key stored in a well-guarded hardware token serves as the "primary" authentication factor (AF) to guarantee strong security; an ephemeral key bound with portable device(s) serves as the "daily-used" AF to achieve high convenience. To protect the subscription pattern and access pattern from leakage, we propose a redactable token generation mechanism, where the users themselves specify what IdP and the service providers can learn from their authentications. We formally define and prove the security of PrivSSO. We also implement a PrivSSO prototype and conduct a comprehensive performance evaluation to demonstrate its practicality.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
江夏完成签到 ,获得积分10
2秒前
金钰贝儿完成签到,获得积分10
4秒前
5秒前
小马甲应助木棉采纳,获得20
7秒前
Li_KK完成签到,获得积分10
9秒前
scanker1981完成签到,获得积分10
15秒前
16秒前
sq完成签到,获得积分10
20秒前
小彭发布了新的文献求助20
23秒前
32秒前
37秒前
自信的叫兽完成签到,获得积分10
38秒前
42秒前
牛八先生完成签到,获得积分10
46秒前
韩雨桐发布了新的文献求助10
47秒前
48秒前
小楠完成签到 ,获得积分20
49秒前
mmyhn发布了新的文献求助10
52秒前
奈何完成签到,获得积分10
53秒前
53秒前
YOLO完成签到 ,获得积分10
54秒前
55秒前
56秒前
苏某发布了新的文献求助10
57秒前
所所应助肖礼成采纳,获得10
59秒前
bcc666发布了新的文献求助10
1分钟前
999完成签到,获得积分10
1分钟前
桐桐应助bcc666采纳,获得10
1分钟前
1分钟前
苏某完成签到,获得积分20
1分钟前
1分钟前
DrLee完成签到,获得积分10
1分钟前
饱满含玉发布了新的文献求助10
1分钟前
852应助欢呼涑采纳,获得30
1分钟前
Shengee发布了新的文献求助10
1分钟前
唯梦完成签到 ,获得积分10
1分钟前
cc完成签到 ,获得积分10
1分钟前
1分钟前
uikymh完成签到 ,获得积分0
1分钟前
1分钟前
高分求助中
Continuum Thermodynamics and Material Modelling 3000
Production Logging: Theoretical and Interpretive Elements 2700
Mechanistic Modeling of Gas-Liquid Two-Phase Flow in Pipes 2500
Structural Load Modelling and Combination for Performance and Safety Evaluation 800
Conference Record, IAS Annual Meeting 1977 610
Interest Rate Modeling. Volume 3: Products and Risk Management 600
Interest Rate Modeling. Volume 2: Term Structure Models 600
热门求助领域 (近24小时)
化学 材料科学 生物 医学 工程类 有机化学 生物化学 物理 纳米技术 计算机科学 内科学 化学工程 复合材料 基因 遗传学 物理化学 催化作用 量子力学 光电子学 冶金
热门帖子
关注 科研通微信公众号,转发送积分 3555687
求助须知:如何正确求助?哪些是违规求助? 3131341
关于积分的说明 9390653
捐赠科研通 2831010
什么是DOI,文献DOI怎么找? 1556280
邀请新用户注册赠送积分活动 726483
科研通“疑难数据库(出版商)”最低求助积分说明 715803