• DocumentCode
    1865142
  • Title

    Single Sign-On Assistant: An Authentication Broker for Web Applications

  • Author

    Zhu, Fei ; Diao, Hongjun

  • Author_Institution
    Sch. of Comput. Sci. & Technol., Soochow Univ., Suzhou, China
  • fYear
    2010
  • fDate
    9-10 Jan. 2010
  • Firstpage
    146
  • Lastpage
    149
  • Abstract
    Web-based systems are now widely used in many fields. Users are usually required to conduct identity authentication separately when logging in different systems before getting service. For the sake of security, it is improper to use a global identifier and password among several systems. Many approaches are proposed to solve the problem, among which single sign-on (SSO) is most popular schema with which a user logs in once and gains access to all systems without having to log in again. We put up a single sign-on assistant, called SSOA, for web-based applications. SSOA is an authentication broker and is implemented as plug-in installed in client side. When a user visits a web-based system using explorer, SSOA distills HTTP POST data, HTTP header used for login, reference address and authorization URI, and then constructs HTTP POST compatible data used for validation using the data returned by authentication broker server. Once a user is validated by SSOA, he can use systems and resources registered in SSOA by means of cached credential list. Due to the cached credential list, SSOA avoid adding excessive additional overhead and response time. SSOA communicates with authentication server via web service by SSL, thus obtaining as much generality as possible. SSOA achieves uniform identity authentication among heterogeneous systems, and attains most generality, simplicity and scalability with least cost as well.
  • Keywords
    Internet; authorisation; message authentication; software architecture; HTTP POST compatible data; HTTP POST data; HTTP header; SSOA; Web application; Web based application; Web based systems; Web service; authentication broker server; authentication server; authorization URI; cached credential list; global identifier; heterogeneous systems; reference address; single sign-on assistant; uniform identity authentication; Application software; Authentication; Authorization; Computer science; Computer security; Costs; Logic; Monitoring; Scalability; Web server; SSL; authentication; plug in; security; single sign on;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Knowledge Discovery and Data Mining, 2010. WKDD '10. Third International Conference on
  • Conference_Location
    Phuket
  • Print_ISBN
    978-1-4244-5397-9
  • Electronic_ISBN
    978-1-4244-5398-6
  • Type

    conf

  • DOI
    10.1109/WKDD.2010.94
  • Filename
    5432692