• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

Computer Engineering & Science

Previous Articles     Next Articles

A cookie-based cross-domain single sign-on scheme

GUO Hao,WANG Guo-cai,LUO Pin   

  1. (School of Information Science and Engineering,Central South University,Changsha 410083,China)
  • Received:2015-11-04 Revised:2016-03-17 Online:2017-07-25 Published:2017-07-25

Abstract:

Aiming at the problem of low efficiency and poor system security due to the multiple authentication of users under multiple application systems, we propose a cookie-based cross-domain single sign-on scheme. Users can login once but access multiple systems in different domains. We provide the overall model of the scheme, analyze the login process and explain the implementation of the cross-domain. The mutual authentication is explained in details, which ensures the legitimate identity of both sides of communication. The management of role-identity is added to reduce the coupling between single sign-on systems and web application systems.
 

Key words: single sign-on, mutual authentication, ticket, role management