Abstract : In this paper we propose a novel scheme that allows Windows CardSpace to be used as a password manager, thereby improving the usability and security of password use as well as potentially encouraging CardSpace adoption. Usernames and passwords are stored in personal cards, and these cards can be used to sign on transparently to corresponding websites. The scheme does not require any changes to login servers or to the CardSpace identity selector and, in particular, it does not require websites to support CardSpace. We describe how the scheme operates, and give details of a proof-of-concept prototype. Security and usability analyses are also provided.
https://hal.inria.fr/hal-01054403
Contributor : Hal Ifip <>
Submitted on : Wednesday, August 6, 2014 - 3:29:58 PM Last modification on : Friday, August 11, 2017 - 3:05:20 PM Long-term archiving on: : Wednesday, November 26, 2014 - 12:51:57 AM
Haitham S. Al-Sinani, Chris J. Mitchell. Using CardSpace as a Password Manager. Second IFIP WG 11.6 Working Conference on Policies and Reseach Management (IDMAN), Nov 2010, Oslo, Norway. pp.18-30, ⟨10.1007/978-3-642-17303-5_2⟩. ⟨hal-01054403⟩