Role of Trust in OAuth 2.0 and OpenID Connect

08/31/2018
by   Kavindu Dodanduwa, et al.
0

OAuth 2.0 is a framework for authorization. Being a framework, OAuth 2.0 allows extensions to build on top of it. OpenID Connect is one such extension which adds authentication layer using identity details. OAuth 2.0 define several roles that are required to complete the protocol. Both OAuth 2.0 and OpenID Connect involve interactions between these roles. These interactions require a pre-established trust or a trust establishment while protocol operate. This paper analyzes trust establishments between OAuth 2.0 roles and discuss important aspects of them. Such analysis is required for proper understanding of the protocols.

READ FULL TEXT
research
07/31/2023

OIDC^2: Open Identity Certification with OpenID Connect

OpenID Connect (OIDC) is a widely used authentication standard for the W...
research
02/28/2022

Pippi: Practical Protocol Instantiation

A protocol specifies interactions between roles, which together constitu...
research
07/29/2018

Trust Based Identity Sharing For Token Grants

Authentication and authorization are two key elements of a software appl...
research
07/17/2023

Reducing Trust in Automated Certificate Authorities via Proofs-of-Authentication

Automated certificate authorities (CAs) have expanded the reach of publi...
research
08/03/2023

VCTP: A Verifiable Credential-based Trust Propagation Protocol for Personal Issuers in Self-Sovereign Identity Platforms

Self Sovereign Identity (SSI) is an emerging identity system that facili...
research
05/13/2019

Enhancing Trust in eAssessment - the TeSLA System Solution

Trust in eAssessment is an important factor for improving the quality of...

Please sign up or login with your details

Forgot password? Click here to reset