An Empirical Study of Security Issues in SSO Server-Side Implementations

Hui Wang,Dawu Gu,Yuanyuan Zhang,Yikun Hu
DOI: https://doi.org/10.1007/s11432-019-2697-1
2021-01-01
Science China Information Sciences
Abstract:>Dear editor, Single sign-on (SSO) schemes have been widely used by major companies to manage service authorization and user authentication. They can enable third-party applications to obtain user information from a service provider to identify a user. The third-party application is often referred to as the relying party (RP), and the service provider is referred to as the identity provider (Id P). According to a recent study [1], OAuth and its extension Open ID connect (OIDC) are amongst the most widespread SSO protocols;
What problem does this paper attempt to address?