Password-Less Authentication Framework for OpenID Systems to Counter Phishing Attacks

Moeen Qaemi Mahmoodzadeh, Haider Abdul Raheem Abbas · Asia-Pacific Services Computing Conference · 2012

OpenID has gained significance for user identity management on the internet. It provides an efficient mechanism for identity management by acting as a third party and independent of the service provider whoever it is. Accessibility and user convenience are the major factors, that OpenID has got acceptance from the web community in a user as well as provider's perspective. But beside these benefits there are also some shortcomings associated with the OpenID mechanism in terms of vulnerabilities and threats in an information security perspective. Phishing is one such attack being practiced by the malicious users to trick the master password that is the core of an OpenID system. Unfortunately a concise solution of this serious threat is still awaited. The paper proposes and validates by use cases, a novel authentication mechanism to counter the phishing attack by using the unclassified user credentials.

Read the paper · More papers on PaperTik