Towards the integration of reputation management in OpenID

  • Authors:
  • Ginés Dólera Tormo;Félix Gómez Mármol;Gregorio Martínez Pérez

  • Affiliations:
  • NEC Europe Ltd., Kurfürsten-Anlage 36, 69115 Heidelberg, Germany;NEC Europe Ltd., Kurfürsten-Anlage 36, 69115 Heidelberg, Germany;Department of Information and Communications Engineering, University of Murcia, Murcia 30100, Spain

  • Venue:
  • Computer Standards & Interfaces
  • Year:
  • 2014

Quantified Score

Hi-index 0.00

Visualization

Abstract

OpenID is an open standard providing a decentralized authentication mechanism to end users. It is based on a unique URL (Uniform Resource Locator) or XRI (Extensible Resource Identifier) as identifier of the user. This fact of using a single identifier confers this approach an interesting added-value when users want to get access to different services in the Internet, since users do not need to create a new account on every website they are visiting. However, OpenID providers are normally used as a point to store certain personal attributes of the end users too, which might be of interest for any service provider willing to make profit from collecting that personal information. The definition of a reputation management solution integrated as part of the OpenID protocol can help users to determine whether a given service provider is more or less reliable before interacting with it and transferring their private information. This paper is providing the definition of a reputation framework that can be applied to the OpenID SSO (Single Sign-On) standard solution. It also defines how the protocol itself can be enhanced so OpenID providers can collect (and provide) recommendations from (to) users regarding different service providers and thus enhancing the users' experience when using OpenID. Besides the definition, a set of tests has been performed validating the feasibility of the framework.