A Billion Keys, but Few Locks: The Crisis of Web Single Sign-On

Fuente: Zenodo
Salvato in:
Dettagli Bibliografici
Autori principali: Sun, San-Tsai, Boshmaf, Yazan, Hawkey, Kirstie, Beznosov, Konstantin
Natura: Recurso digital
Pubblicazione: Zenodo 2010
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866901467577712640
author Sun, San-Tsai
Boshmaf, Yazan
Hawkey, Kirstie
Beznosov, Konstantin
author_facet Sun, San-Tsai
Boshmaf, Yazan
Hawkey, Kirstie
Beznosov, Konstantin
contents OpenID and InfoCard are two mainstream Web single sign-on (SSO) solutions intended for Internet-scale adoption. While they are technically sound, the business model of these solutions does not provide content-hosting and service providers (CSPs) with sufficient incentives to become relying parties (RPs). In addition, the pressure from users and identity providers (IdPs) is not strong enough to drive CSPs toward adopting Web SSO. As a result, there are currently over one billion OpenID-enabled user accounts provided by major CSPs, but only a few relying parties. In this paper, we discuss the problem of Web SSO adoption for RPs and argue that solutions in this space must offer RPs sufficient business incentives and trustworthy identity services in order to succeed. We suggest future Web SSO development should investigate RPs' business needs, identify IdP business models, and build trust frameworks. Moreover, we propose that Web SSO technology should shift from its current shared-identity paradigm to a true Web single sign-on and sign-out experience in order to function as a platform to motivate RPs' adoption.
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_3264480
institution Zenodo
language
publishDate 2010
publisher Zenodo
record_format zenodo
spellingShingle A Billion Keys, but Few Locks: The Crisis of Web Single Sign-On
Sun, San-Tsai
Boshmaf, Yazan
Hawkey, Kirstie
Beznosov, Konstantin
Web Single Sign-On
Web Identity Management
Authentication
OpenID
InfoCard
issnet
OpenID and InfoCard are two mainstream Web single sign-on (SSO) solutions intended for Internet-scale adoption. While they are technically sound, the business model of these solutions does not provide content-hosting and service providers (CSPs) with sufficient incentives to become relying parties (RPs). In addition, the pressure from users and identity providers (IdPs) is not strong enough to drive CSPs toward adopting Web SSO. As a result, there are currently over one billion OpenID-enabled user accounts provided by major CSPs, but only a few relying parties. In this paper, we discuss the problem of Web SSO adoption for RPs and argue that solutions in this space must offer RPs sufficient business incentives and trustworthy identity services in order to succeed. We suggest future Web SSO development should investigate RPs' business needs, identify IdP business models, and build trust frameworks. Moreover, we propose that Web SSO technology should shift from its current shared-identity paradigm to a true Web single sign-on and sign-out experience in order to function as a platform to motivate RPs' adoption.
title A Billion Keys, but Few Locks: The Crisis of Web Single Sign-On
topic Web Single Sign-On
Web Identity Management
Authentication
OpenID
InfoCard
issnet
url https://doi.org/10.5281/zenodo.3264480