Implementing Strong Authentication Interoperability with Legacy Systems [chapter]

Jan Zibuschka, Heiko Roßnagel
Policies and Research in Identity Management  
In a WWW environment, users need to come up with passwords for a lot of different services, e.g. in the area of e-commerce. These authentication secrets need to be unrelated if the user does not want to make himself vulnerable to insider attacks. This leads to a large number of passwords that a user has to generate, memorize, and remember. This password management is quite straining for users. Single sign on systems provide a solution for this dilemma. However, existing solutions often require
more » ... he implementation of specific interfaces by the individual service providers, and usually do not support existing strong authentication factors, e.g. smart cards, without protocol extensions or modification of implementations. In this paper we propose a different approach that generates strong passwords using electronic signatures. Our approach builds on existing smart card infrastructures to achieve strong authentication, while at the same time it provides an interface to legacy password authentication systems. Please use the following format when citing this chapter:
doi:10.1007/978-0-387-77996-6_12 dblp:conf/idman/ZibuschkaR07 fatcat:k5jidubag5h3pjd6jo4gz2r574