Transaction signing in applications using identity federation
Paul Rabinovich · 2010
Many applications require users to express their consent when executing transactions on the Web. Transaction signing with passwords is by far the most common mechanism for providing such consent. An application that uses identity federation may not share a password with the user and, therefore, cannot engage in a password-based signing protocol. In this paper we propose a protocol that does not require users to share their passwords with applications (service providers) but only relies on passwords shared between users and their identity providers.