skip to main content
10.1145/2070425.2070467acmotherconferencesArticle/Chapter ViewAbstractPublication PagessinConference Proceedingsconference-collections
short-paper

Extending the Scope of cardspace

Published:14 November 2011Publication History

ABSTRACT

The recently-proposed PassCard scheme enables CardSpace to be used as a password manager, thereby both improving the usability and security of passwords as well as encouraging CardSpace adoption. However, this scheme does not work with sites using HTTPS, seriously limiting its practicality. In this paper we extend PassCard to support sites using both HTTP and HTTPS. Usernames and passwords are stored in CardSpace personal cards, and these cards can be used to sign on transparently to corresponding websites. PassCard does not require any changes to login servers, default browser security settings or to the CardSpace identity selector; in particular, it does not require websites to support CardSpace. PassCard operates with both the CardSpace and the Higgins identity selectors without any modification. We describe how this new version of PassCard operates, and give security and usability analyses.

References

  1. H. S. Al-Sinani and C. J. Mitchell. Implementing PassCard -- a CardSpace-based Password Manager. Technical Report: RHUL--MA--2010--15 (Department of Mathematics, Royal Holloway, University of London), 2010. http://www.ma.rhul.ac.uk/static/techrep/2010/RHUL-MA-2010--15.pdf.Google ScholarGoogle Scholar
  2. H. S. Al-Sinani and C. J. Mitchell. Using CardSpace as a password manager. In E. de Leeuw, S. Fischer-Hübner, and L. Fritsch, editors, Proceedings of IFIP IDMAN'10, volume 343 of IFIP Advances in Information and Communication Technology, pages 18--30. Springer, Boston, 2010.Google ScholarGoogle Scholar
  3. H. S. Al-Sinani and C. J. Mitchell. Client-based CardSpace-OpenID interoperation. In Proceedings of ISCIS'11. Springer {LNEE}, (to appear), 2011.Google ScholarGoogle ScholarCross RefCross Ref
  4. H. S. Al-Sinani and C. J. Mitchell. Enhancing CardSpace authentication using a mobile device. In Y. Li, editor, Proceedings of DBSEC'11, volume 6818, pages 201--216. Springer (LNCS), 2011. Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. C. Herley, P. C. van Oorschot, and A. S. Patrick. Passwords: If we're so smart, why are we still using them? In R. Dingledine and P. Golle, editors, Financial Cryptography and Data Security, volume 5628, Springer-Verlag (LNCS), 230--237, 2009. Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. M. B. Jones and M. McIntosh (editors). Identity Metasystem Interoperability Version 1.0. OASIS, 2009.Google ScholarGoogle Scholar
  7. M. Mercuri. Beginning Information Cards and CardSpace: From Novice to Professional. Apress, New York, 2007. Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. Extending the Scope of cardspace

    Recommendations

    Comments

    Login options

    Check if you have access through your login credentials or your institution to get full access on this article.

    Sign in
    • Published in

      cover image ACM Other conferences
      SIN '11: Proceedings of the 4th international conference on Security of information and networks
      November 2011
      276 pages
      ISBN:9781450310208
      DOI:10.1145/2070425

      Copyright © 2011 ACM

      Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      • Published: 14 November 2011

      Permissions

      Request permissions about this article.

      Request Permissions

      Check for updates

      Qualifiers

      • short-paper

      Acceptance Rates

      Overall Acceptance Rate102of289submissions,35%

    PDF Format

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader