The Security Limitations of SSO in OpenID

Hyun-Kyung Oh, Seunghun Jin · International Conference on Advanced Communication Technology · 2008

As the Internet becomes a way of social life, there are lots of accounts which a user has to manage. To receive the Web service, people have to register each Web site. It is the OpenID to resolve these burdensome. The OpenID provides the single sign-on service which a user can be authenticated in several Web sites by submitting the password of OpenID to authentication server only once. In this paper, we analyze the single sign-on in OpenID and show an experiment of vulnerability of OpenID.

Read the paper · More papers on PaperTik