IC card-based single sign-on system that remains secure under card analysis

  • Authors:
  • Jun Furukawa;Kazue Sako;Satoshi Obana

  • Affiliations:
  • NEC Corporation, Kawasaki, Japan;NEC Corporation, Kawasaki, Japan;NEC Corporation, Kawasaki, Japan

  • Venue:
  • Proceedings of the 5th ACM workshop on Digital identity management
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Today, many users of the network access to multiple independent services consecutively or even simultaneously. Single sign-on systems help such users to access services easily with only a single log-in process. Some single sign-on systems that require users' IC cards be authenticated directly by services, achieve high level of security in that they allow no third party to have the power to impersonate users. However, most of these systems are vulnerable when IC cards are analyzed since the security is solely dependent on the secret information born in side the card. In this paper, we propose a novel single sign-on system with IC card that still keeps certain level of security even when user's IC card is analyzed. In the system, secret information is kept distributedly in IC card and portal.