Title :
A secure SSO protocol without clock synchronization
Author :
Sha, Shi ; Yan, Wen Qiao ; Ming Zhu Li
Author_Institution :
State Key Lab. of Networking & Switching Technol., Beijing Univ. of Posts & Telecommun., Beijing, China
Abstract :
To secure the SSO process, a timestamp is usually used in the SSO protocol to prevent the replay attack. The clock synchronization between the servers and clients is required for timestamp-based SSO mechanism, in reality, it is difficult to keep the clock of the engaged servers and clients synchronized. We designed a SSO protocol which doesn´t require the clock synchronization of the servers and clients, while the replay attack still can be prevented.
Keywords :
computer network security; network servers; protocols; synchronisation; SSO protocol security; clock synchronization; replay attack; single sign on protocol; Servers; Telecommunications; Variable speed drives; Clock Synchronization; Protocol; SSO;
Conference_Titel :
Advanced Computer Theory and Engineering (ICACTE), 2010 3rd International Conference on
Conference_Location :
Chengdu
Print_ISBN :
978-1-4244-6539-2
DOI :
10.1109/ICACTE.2010.5579853