Security Analysis of OpenID.

Pavol Sovis, Florian Kohlar, Jörg Schwenk · 2010

Abstract: OpenID is auser-centric and decentralized Single Sign-On system. It enables users to sign into Relying Partiesby providing an authentication assertion from an OpenID Provider. Itissupported by many leading internet companies and there are over abillion accounts capable of using OpenID. We present asecurity analysis of OpenID and the corresponding extensions and reveal several vulnerabilities. This paper demonstrates how identity information sent within the OpenID protocol can be manipulated, due to an improper verification of OpenID assertions and no integrity protection of the authentication request. 1

Read the paper · More papers on PaperTik