Using CardSpace as a Password Manager
Abstract
In this paper we propose a novel scheme that allows Windows CardSpace to be used as a password manager, thereby improving the usability and security of password use as well as potentially encouraging CardSpace adoption. Usernames and passwords are stored in personal cards, and these cards can be used to sign on transparently to corresponding websites. The scheme does not require any changes to login servers or to the CardSpace identity selector and, in particular, it does not require websites to support CardSpace. We describe how the scheme operates, and give details of a proof-of-concept prototype. Security and usability analyses are also provided.
Domains
Digital Libraries [cs.DL]
Fichier principal
CardSpace_Password_Manager_28CPM_29_IDman2010_Final.pdf (206.3 Ko)
Télécharger le fichier
Origin | Files produced by the author(s) |
---|
Loading...