A hybrid approach for highly available and secure storage of Pseudo-SSO credentials

  • Authors:
  • Jan Zibuschka;Lothar Fritsch

  • Affiliations:
  • Fraunhofer IAO, Stuttgart, Germany;Norsk Regnesentral, Oslo, Norway

  • Venue:
  • NordSec'12 Proceedings of the 17th Nordic conference on Secure IT Systems
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

We present a novel approach for password/credential storage in Pseudo-SSO scenarios based on a hybrid password hashing/password syncing approach that is directly applicable to the contemporary Web. The approach supports passwords without requiring modification of the server side and thus is immediately useful; however, it may still prove useful for storing more advanced credentials in future SSO and identity management scenarios, and offers a high password security, high availability and integration of secure elements while providing familiar interaction paradigms at a low cost.