• DocumentCode
    1812640
  • Title

    A Novel Distributed Single Sign-On Scheme with Dynamically Changed Threshold Value

  • Author

    Zhong, Shangping ; Liao, Xiangwen ; Zhang, Xue ; Lin, Jingqu

  • Author_Institution
    Dept. of Comput. Sci. & Technol., Fuzhou Univ., Fuzhou, China
  • Volume
    2
  • fYear
    2009
  • fDate
    18-20 Aug. 2009
  • Firstpage
    563
  • Lastpage
    566
  • Abstract
    A single sign-on (SSO) system allow single authentication for multiple services. It is a potential solution to the implications of security, credentials management, et al. Recently, several works have used the threshold-based secret sharing scheme to create a distributed SSO service. All these works setup the threshold parameters first in the system initiation. But in some real-world applications, the threshold value should be dynamically changed in the authentication phase. In this paper, we present a novel threshold-based distributed single sign-on scheme with a dynamically changed threshold value(DctSSO). In DctSSO, two different degree secret polynomials are constructed. Each authentication server has two kinds of secret keys: keys for initiation shares and keys for authentication shares. Through the simply XOR operation, authentication shares keys can be delivered securely. DctSSO is not only as good as Threspassport on the aspects of security, portability, intrusion and fault tolerance, scalability, reliability, and availability, but also it offers two significant advantages over ThresPassport : it has the dynamically, securely and availably changed threshold value in the authentication phase, and it can prevent conspiracy-impersonation attacks.
  • Keywords
    authorisation; message authentication; XOR operation; authentication; conspiracy-impersonation attacks; distributed single sign-on scheme; dynamically changed threshold value; secret polynomials; threshold-based secret sharing scheme; Authentication; Availability; Computer science; Computer security; Cryptography; Fault tolerance; Information security; Network servers; Polynomials; Scalability; DctSSO; Single Sign-On scheme; conspiracy-impersonation attack; dynamically changed threshold value; threshold-based;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance and Security, 2009. IAS '09. Fifth International Conference on
  • Conference_Location
    Xian
  • Print_ISBN
    978-0-7695-3744-3
  • Type

    conf

  • DOI
    10.1109/IAS.2009.194
  • Filename
    5283739