Download presentation
Presentation is loading. Please wait.
Published byEleanore Owens Modified over 8 years ago
1
1 The Quest for Single-Sign On Prof. Ravi Sandhu Executive Director and Endowed Chair February 8, 2013 ravi.sandhu@utsa.edu www.profsandhu.com © Ravi Sandhu World-Leading Research with Real-World Impact! CS 6393 Lecture 4.sso
2
© Ravi Sandhu 2 World-Leading Research with Real-World Impact! Gorman 2003 We will discuss SSO separately Initial authentication Session establishment and maintenance to authentication server Authentication to multiple servers Session establishment and mantenance at multiple servers Single logout
3
© Ravi Sandhu 3 World-Leading Research with Real-World Impact! User-Authenticator-Attribute Triangle User AttributeAuthenticator
4
© Ravi Sandhu 4 World-Leading Research with Real-World Impact! User-Authenticator-Attribute Triangle User AttributeAuthenticator X.509 identity certificate X.509 attribute certificate SPKI certificate 1990s
5
© Ravi Sandhu 5 World-Leading Research with Real-World Impact! User-Authenticator-Attribute Triangle User AttributeAuthenticator SAML assertion SAML assertion SAML assertion 2000s
6
© Ravi Sandhu 6 World-Leading Research with Real-World Impact! Taxonomy 2003 SSO: single sign on SP: service provider (also called relying party) ASP: authentication service provider Pseudo SSO Identity to SP is n to 1 True SSO Identity to SP is n to m
7
© Ravi Sandhu 7 World-Leading Research with Real-World Impact! Taxonomy 2003 3.1 and 3.2 Pseudo SSO: authenticate True SSO: pass assertions Local: to user platform Proxy: provided by external platform Local, Pseudo Proxy, Pseudo Local, True Proxy, True
8
© Ravi Sandhu 8 World-Leading Research with Real-World Impact! Taxonomy 2003 PKI (Public Key Infrastructure) does not fall neatly into this characterization User Private Key SP1 SP2 SP3 Authenticated, confidential channels 2-way SSL also known as mutually authenticated SSL
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.