CAS++: An Open Source Single Sign-On Solution for Secure e-Services
نویسندگان
چکیده
Business and recreational activities on the global communication infrastructure are increasingly based on the use of remote resources and services, and on the interaction between different, remotely located parties. On corporate networks as well as on the open Web, the huge number of resources and services often requires to multiple log-ons leading to credential proliferation and, potentially, to security leaks. An increasingly widespread approach to simplify and secure the log-on process is Single Sign-On (SSO) that allows automatic access to secondary domains through a single log-on operation to a primary domain. In this paper, we describe the basic concepts of SSO architecture focusing on the central role of open source implementations. We outline three major SSO trust models and the different requirements to be addressed. We then illustrate CAS++, our open source implementation of a Single Sign-On service. Finally, we illustrate the application of CAS++ to a real case study concerning the development of a multi-service network management system. The motivation for our work has been raised in response to the requirements of such case study within the Pitagora project.
منابع مشابه
Secure Authentication Process for High Sensitive Data E-Services: A Roadmap
The widespread diffusion of online services provided by public and private organizations, firstly driven by e-commerce and more recently by e-government applications, has stressed the need of secure ways to authenticate users who need to access online resources. The huge number of resources accessible on the Web leads to different authentication mechanisms implementations that often require mul...
متن کاملESUP-Portail: open source Single Sign-On with CAS (Central Authentication Service)
The universality of the HTTP protocol seduced developers for quite long; most applications are web-based today. LDAP directories saved our users’ brains by making them memorize only one password, but their fingers are still very much in demand by all the authentications they need to type, in practice each time they access an application. Many solutions for Single Sign-On are already available. ...
متن کاملProxy Authenticator - Approach of a Signature-based Single Sign On Solution for E-Government Services
This paper illustrates the development of an e-government solution for an application of a single-sign-on technology without the use of the SAML V2.0 protocol. We were confronted with the task of creating and implementing this kind of secure system, running on myHelp.gv.at, which is one of the Austrian eGovernment Portals. The solution – or as we call it ‘proxy authenticator’ – enables us to om...
متن کاملThe Security of Web Services: Secure Communication and Identity Management
Service Oriented Architectures have become the new trend in the world of communication on the web. Especially web services are the high-performance specification of service-oriented architectures. The use of confidential data on the Web becomes the primary problem in the secure communication over the web. The solution proposed in this paper is a secure communication tool OCS based on the princi...
متن کاملA Distributed Authentication Model for an E-Health Network Using Blockchain
Introduction: One of the most important and challenging areas under the influence of information technology is the field of health. This pervasive influence has led to the development of electronic health (e-health) networks with a variety of services of different qualities. The issue of security management, maintaining confidentiality and data integrity, and exchanging it in a secure environme...
متن کامل