ROSTAM: A Passwordless Web Single Sign-on Solution Mitigating Server Breaches and Integrating Credential Manager and Federated Identity Systems
Amin Mahnamfar, Kemal Bicakci, Yusuf Uzunay

TL;DR
ROSTAM is a novel passwordless web SSO system that enhances security by using a Master Key instead of passwords, integrating credential management and federated identity for a seamless user experience.
Contribution
The paper introduces ROSTAM, a new passwordless SSO solution with innovative Master Key synchronization and recovery techniques, combining credential management and federated identity benefits.
Findings
ROSTAM provides a secure, passwordless SSO with a user-friendly dashboard.
The Master Key approach enhances security even if server data is compromised.
Evaluation shows ROSTAM outperforms previous solutions in security and usability.
Abstract
The challenge of achieving passwordless user authentication is real given the prevalence of web applications that keep asking passwords. Complicating this issue further, in an enterprise environment, a single sign-on (SSO) service is often maintained but not all applications can be integrated with it. We envision a passwordless future which provides a frictionless and trustworthy online experience for users by integrating credential management and federated identity systems. In this regard, our implementation ROSTAM offers a dashboard that presents all applications the user can access with a single click after a passwordless SSO. The security of web passwords on the credential manager is ensured with a Master Key, rather than a Master Password, so that encrypted passwords can remain secure even if stolen from the server. We propose and implement novel techniques for synchronization…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Privacy, Security, and Data Protection · Advanced Authentication Protocols Security
