A secure SSO protocol without clock synchronization
Sha Shi, Wen Qiao Yan, Ming Zhu Li · 2010
To secure the SSO process, a timestamp is usually used in the SSO protocol to prevent the replay attack. The clock synchronization between the servers and clients is required for timestamp-based SSO mechanism, in reality, it is difficult to keep the clock of the engaged servers and clients synchronized. We designed a SSO protocol which doesn't require the clock synchronization of the servers and clients, while the replay attack still can be prevented.