A Mechanism to Prevent RP Phishing in OpenID System

Jae-Hwe You, Moon-Seog Jun · 2010

Even though users have been assigned IDs after being authenticated by their real names and resident registration numbers for using Internet services, the I-PIN (Internet Personal Identification Number) service, which is a substitution means for the resident registration number, is recently applied because of security problem. In addition, the OpenID service, which could receive Internet service by integrating into a single ID, is now in force within the country, however, it could be wrongfully used as abusive comments and spam and is pointed out as problems for phishing since it has not user authentications. This paper proposes a technique to strengthen user authentications with the I-PIN when users sign up for memberships in the OpenID, and compensates the phishing problem of relaying parties (RPs) which users could receive Internet service with the OpenID. It could be found that the user authentication and the security of the OpenID are strengthened by comparison and analysis between the existing OpenID service and the OpenID service applying the I-PIN proposed in this paper, and it is designed enough to be safe for phishing.

Read the paper · More papers on PaperTik