Toward A Secure Single Sign-On Mechanism for Distributed Computer Networks
Cheng‐Chi Lee, Yan-Ming Lai · The Computer Journal · 2014
Single sign-on (SSO) is a new authentication mechanism for the distributed computer network. It allows a legal user to sign-on to multiple servers with a single credential in distributed computer networks. Recently, Chang and Lee have proposed a SSO scheme and claimed that their scheme is secure. However, as Wang et al. pointed out, there are two leaks in Chang–Lee scheme. The first leak allows a malicious service provider to obtain a legal user's single credential and impersonate the user to access resources offered by other service providers. The other leak allows an outside attacker to forge a credential and use the forged credential to sign-on to the legal servers. Unfortunately, Wang et al. have not offered any suggestions as to how to mend the leaks. In this paper, we shall point out the third leak of the Chang–Lee scheme and propose a solution to remedy all three of these leaks. The solution will upgrade not only the security level but also the performance efficiency of the Chang–Lee scheme.