Presentation is loading. Please wait.

Presentation is loading. Please wait.

1 The Quest for Single-Sign On Prof. Ravi Sandhu Executive Director and Endowed Chair February 8, 2013 © Ravi Sandhu.

Similar presentations


Presentation on theme: "1 The Quest for Single-Sign On Prof. Ravi Sandhu Executive Director and Endowed Chair February 8, 2013 © Ravi Sandhu."— Presentation transcript:

1 1 The Quest for Single-Sign On Prof. Ravi Sandhu Executive Director and Endowed Chair February 8, 2013 ravi.sandhu@utsa.edu www.profsandhu.com © Ravi Sandhu World-Leading Research with Real-World Impact! CS 6393 Lecture 4.sso

2 © Ravi Sandhu 2 World-Leading Research with Real-World Impact! Gorman 2003 We will discuss SSO separately  Initial authentication  Session establishment and maintenance to authentication server  Authentication to multiple servers  Session establishment and mantenance at multiple servers  Single logout

3 © Ravi Sandhu 3 World-Leading Research with Real-World Impact! User-Authenticator-Attribute Triangle User AttributeAuthenticator

4 © Ravi Sandhu 4 World-Leading Research with Real-World Impact! User-Authenticator-Attribute Triangle User AttributeAuthenticator X.509 identity certificate X.509 attribute certificate SPKI certificate 1990s

5 © Ravi Sandhu 5 World-Leading Research with Real-World Impact! User-Authenticator-Attribute Triangle User AttributeAuthenticator SAML assertion SAML assertion SAML assertion 2000s

6 © Ravi Sandhu 6 World-Leading Research with Real-World Impact! Taxonomy 2003 SSO: single sign on SP: service provider (also called relying party) ASP: authentication service provider Pseudo SSO Identity to SP is n to 1 True SSO Identity to SP is n to m

7 © Ravi Sandhu 7 World-Leading Research with Real-World Impact! Taxonomy 2003 3.1 and 3.2 Pseudo SSO: authenticate True SSO: pass assertions Local: to user platform Proxy: provided by external platform Local, Pseudo Proxy, Pseudo Local, True Proxy, True

8 © Ravi Sandhu 8 World-Leading Research with Real-World Impact! Taxonomy 2003 PKI (Public Key Infrastructure) does not fall neatly into this characterization User Private Key SP1 SP2 SP3 Authenticated, confidential channels 2-way SSL also known as mutually authenticated SSL


Download ppt "1 The Quest for Single-Sign On Prof. Ravi Sandhu Executive Director and Endowed Chair February 8, 2013 © Ravi Sandhu."

Similar presentations


Ads by Google