KAuth: A Strong Single Sign-On Service based on PKI
Author(s) -
Panayiotis Charalambous,
Marios Karapetris,
Ηλίας Αθανασόπουλος
Publication year - 2018
Publication title -
proceedings of the 15th international joint conference on e-business and telecommunications
Language(s) - English
Resource type - Conference proceedings
DOI - 10.5220/0006851906440649
Subject(s) - public key infrastructure , single sign on , computer science , sign (mathematics) , computer security , public key cryptography , authentication (law) , mathematics , encryption , mathematical analysis
We deploy PKI for human authentication. We use a publicly available infrastructure, namely Keybase, for managing public-key pairs across devices. In addition, Keybase offers us several features for identifying users in social networks and a login-to-Keybase process which is password-less, meaning that authentication takes place using digital signatures produced by an Elliptic Curve (EC) cryptosystem. By using Keybase, we minimize the required cryptographic keys to the absolute minimum: one. We transform Keybase to a Single Sign-On (SSO) service which can vet users for using other services, exactly as it happens now with very popular, but entirely password-based, services. We implement two authentication schemes based on Keybase, KAuth and KAuth+, and we evaluate them using a state-of-the-art methodology.
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom