OIDC^2: Open Identity Certification with OpenID Connect

07/31/2023
by   Jonas Primbs, et al.
0

OpenID Connect (OIDC) is a widely used authentication standard for the Web. In this work, we define a new Identity Certification Token (ICT) for OIDC. An ICT can be thought of as a JSON-based, short-lived user certificate for end-to-end user authentication without the need for cumbersome key management. A user can request an ICT from his OpenID Provider (OP) and use it to prove his identity to other users or services that trust the OP. We call this approach OIDC^2 and compare it to other well-known end-to-end authentication methods. Unlike certificates, OIDC^2 does not require installation and can be easily used on multiple devices, making it more user-friendly. We outline protocols for implementing OIDC^2 based on existing standards. We discuss the trust relationship between entities involved in OIDC^2, propose a classification of OPs' trust level, and propose authentication with multiple ICTs from different OPs. We explain how different applications such as videoconferencing, instant messaging, and email can benefit from ICTs for end-to-end authentication and recommend validity periods for ICTs. To test OIDC^2, we provide a simple extension to existing OIDC server software and evaluate its performance.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/29/2018

Trust Based Identity Sharing For Token Grants

Authentication and authorization are two key elements of a software appl...
research
07/17/2023

Reducing Trust in Automated Certificate Authorities via Proofs-of-Authentication

Automated certificate authorities (CAs) have expanded the reach of publi...
research
08/31/2018

Role of Trust in OAuth 2.0 and OpenID Connect

OAuth 2.0 is a framework for authorization. Being a framework, OAuth 2.0...
research
08/21/2023

SCC5G: A PQC-based Architecture for Highly Secure Critical Communication over Cellular Network in Zero-Trust Environment

5G made a significant jump in cellular network security by offering enha...
research
05/13/2019

Enhancing Trust in eAssessment - the TeSLA System Solution

Trust in eAssessment is an important factor for improving the quality of...
research
11/26/2019

Device-Free User Authentication, Activity Classification and Tracking using Passive Wi-Fi Sensing: A Deep Learning Based Approach

Privacy issues related to video camera feeds have led to a growing need ...
research
12/04/2018

Continuous User Authentication by Contactless Wireless Sensing

This paper presents BodyPIN, which is a continuous user authentication s...

Please sign up or login with your details

Forgot password? Click here to reset