Password Policy Markup Language
نویسندگان
چکیده
Password-based authentication is the most widely used authentication scheme for granting access to user accounts on the Internet. Despite this, there exists no standard implementation of passwords by services. They have different password requirements as well as interfaces and procedures for login, password change, and password reset. This situation is very challenging for users and often leads to the choice of weak passwords and prevents security-conscious behavior. Furthermore, it prevents the development of applications that provide a fully-fledged assistance for users in securely generating and managing passwords. In this paper, we present a solution that bridges the gap between the different password implementations on the service-side and applications assisting users with their passwords on the client-side. First, we introduce the Password Policy Markup Language (PPML). It enables a uniformly specified Password Policy Description (PPD) for a services. A PPD describes the password requirements as well as password interfaces and procedures of a service and can be processed by applications. It enables applications to automatically (1) generate passwords in accordance with the password requirements of a service, (2) perform logins, (3) change passwords, and (4) reset passwords. Second, we present a prototypical password manager which uses PPDs and is capable of generating and completely managing passwords on behalf of users.
منابع مشابه
Web Single Sign-On Systems
Currently, many web applications require users to register for a new account. With the proliferation of web applications, it has become impractical to expect users to remember different usernames and passwords for each application. Web Single Sign-On (Web SSO) protocols allow users to use a s ingle username and password to access different applications. This paper examines three Web SSO protoco...
متن کاملIdentification and Authentication in Networks enabling Single Sign-On
Identification and authentication is every days business for users in todays Internet. Therefore, every user has to tackle with an increasing number of usernames and passwords. Usually every username and password belongs to an isolated account which can be considered as a security domain. As a result, users are stressed with handling so many credentials. On the other hand, to realize the cooper...
متن کاملIntroducing Community Single Sign-On for EDIT
The European Distributed Institute of Taxonomy (EDIT) platform, as well as biodiversity providers in general, provides a multitude of web-based taxonomic applications and services. Also, the diversity of service providers reflects the highly distributed, cross-national organisational infrastructure of taxonomic institutions and collections. This results in a problem of identity management. Whil...
متن کاملXACML Policies for Exclusive Resource Usage
The extensible access control markup language (XACML) is the standard access control policy specification language of the World Wide Web. XACML does not provide exclusive accesses to globally resources. We do so by enhancing the policy execution framework with locks.
متن کاملXPACML eXtensible Privacy Access Control Markup Language
Privacy in the digital world is a critical problem which is becoming even more imperious with the growth of the Internet, accompanied by the proliferation of e-services (e.g. ecommerce, e-health). One research track for efficient privacy management is to make use of user’s and service provider’s (SP) privacy policies, and to perform an automatic comparison in between to help any (skilled or uns...
متن کامل