Extending the Scope of CardSpace

Al-Sinani, Haitham S and Mitchell, Chris J

(2011)

Al-Sinani, Haitham S and Mitchell, Chris J (2011) Extending the Scope of CardSpace
In: Proceedings of the 4th International Conference on Security of Information and Networks, SIN 2011, Sydney, NSW, Australia, November 14-19, 2011. ACM.

Our Full Text Deposits

Full text access: Open

Full text file - 212.71 KB

Abstract

The recently-proposed PassCard scheme enables CardSpace to be used as a password manager, thereby both improving the usability and security of passwords as well as encouraging CardSpace adoption. However, this scheme does not work with sites using HTTPS, seriously limiting its practicality. In this paper we extend PassCard to support sites using both HTTP and HTTPS. Usernames and passwords are stored in CardSpace personal cards, and these cards can be used to sign on transparently to corresponding websites. PassCard does not require any changes to login servers, default browser security settings or to the CardSpace identity selector; in particular, it does not require websites to support CardSpace. PassCard operates with both the CardSpace and the Higgins identity selectors without any modification. We describe how this new version of PassCard operates, and give security and usability analyses.

Information about this Version

This is a Submitted version
This version's date is: 2011
This item is not peer reviewed

Link to this Version

https://repository.royalholloway.ac.uk/items/28202256-639a-866c-a096-873f06c67a10/3/

Item TypeBook Item
TitleExtending the Scope of CardSpace
AuthorsAl-Sinani, Haitham S
Mitchell, Chris J
Uncontrolled KeywordsCardSpace, Password Manager, Browser Extension
DepartmentsFaculty of Science\Mathematics

Identifiers

Deposited by Research Information System (atira) on 19-Sep-2012 in Royal Holloway Research Online.Last modified on 19-Sep-2012


Details