{"id":"https://openalex.org/W4385522578","doi":"https://doi.org/10.56553/popets-2023-0100","title":"Save The Implicit Flow? Enabling Privacy-Preserving RP Authentication in OpenID Connect","display_name":"Save The Implicit Flow? Enabling Privacy-Preserving RP Authentication in OpenID Connect","publication_year":2023,"publication_date":"2023-08-03","ids":{"openalex":"https://openalex.org/W4385522578","doi":"https://doi.org/10.56553/popets-2023-0100"},"language":"en","primary_location":{"id":"doi:10.56553/popets-2023-0100","is_oa":true,"landing_page_url":"https://doi.org/10.56553/popets-2023-0100","pdf_url":"https://petsymposium.org/popets/2023/popets-2023-0100.pdf","source":{"id":"https://openalex.org/S4210183172","display_name":"Proceedings on Privacy Enhancing Technologies","issn_l":"2299-0984","issn":["2299-0984"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320322","host_organization_name":"De Gruyter Open","host_organization_lineage":["https://openalex.org/P4310320322","https://openalex.org/P4310313990"],"host_organization_lineage_names":["De Gruyter Open","De Gruyter"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings on Privacy Enhancing Technologies","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://petsymposium.org/popets/2023/popets-2023-0100.pdf","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5092589281","display_name":"Maximilian Kroschewski","orcid":null},"institutions":[{"id":"https://openalex.org/I143288331","display_name":"Hasso Plattner Institute","ror":"https://ror.org/058rn5r42","country_code":"DE","type":"facility","lineage":["https://openalex.org/I143288331","https://openalex.org/I176453806"]},{"id":"https://openalex.org/I176453806","display_name":"University of Potsdam","ror":"https://ror.org/03bnmw459","country_code":"DE","type":"education","lineage":["https://openalex.org/I176453806"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Maximilian Kroschewski","raw_affiliation_strings":["Hasso Plattner Institute, University of Potsdam"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Hasso Plattner Institute, University of Potsdam","institution_ids":["https://openalex.org/I143288331","https://openalex.org/I176453806"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5044041318","display_name":"Anja Lehmann","orcid":"https://orcid.org/0000-0002-2872-7899"},"institutions":[{"id":"https://openalex.org/I143288331","display_name":"Hasso Plattner Institute","ror":"https://ror.org/058rn5r42","country_code":"DE","type":"facility","lineage":["https://openalex.org/I143288331","https://openalex.org/I176453806"]},{"id":"https://openalex.org/I176453806","display_name":"University of Potsdam","ror":"https://ror.org/03bnmw459","country_code":"DE","type":"education","lineage":["https://openalex.org/I176453806"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Anja Lehmann","raw_affiliation_strings":["Hasso Plattner Institute, University of Potsdam"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Hasso Plattner Institute, University of Potsdam","institution_ids":["https://openalex.org/I143288331","https://openalex.org/I176453806"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.979,"has_fulltext":true,"cited_by_count":6,"citation_normalized_percentile":{"value":0.80406679,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":98},"biblio":{"volume":"2023","issue":"4","first_page":"96","last_page":"116"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9839000105857849,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9839000105857849,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11504","display_name":"Advanced Authentication Protocols Security","score":0.9587000012397766,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.9510999917984009,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8282254934310913},{"id":"https://openalex.org/keywords/security-token","display_name":"Security token","score":0.7279940843582153},{"id":"https://openalex.org/keywords/login","display_name":"Login","score":0.6947398781776428},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.6779507994651794},{"id":"https://openalex.org/keywords/authentication","display_name":"Authentication (law)","score":0.6376903057098389},{"id":"https://openalex.org/keywords/single-sign-on","display_name":"Single sign-on","score":0.6150189638137817},{"id":"https://openalex.org/keywords/protocol","display_name":"Protocol (science)","score":0.5386857986450195},{"id":"https://openalex.org/keywords/authentication-protocol","display_name":"Authentication protocol","score":0.4967196583747864},{"id":"https://openalex.org/keywords/identity","display_name":"Identity (music)","score":0.48864322900772095},{"id":"https://openalex.org/keywords/scheme","display_name":"Scheme (mathematics)","score":0.4809540808200836}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8282254934310913},{"id":"https://openalex.org/C48145219","wikidata":"https://www.wikidata.org/wiki/Q1335365","display_name":"Security token","level":2,"score":0.7279940843582153},{"id":"https://openalex.org/C113324615","wikidata":"https://www.wikidata.org/wiki/Q472302","display_name":"Login","level":2,"score":0.6947398781776428},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6779507994651794},{"id":"https://openalex.org/C148417208","wikidata":"https://www.wikidata.org/wiki/Q4825882","display_name":"Authentication (law)","level":2,"score":0.6376903057098389},{"id":"https://openalex.org/C2776362682","wikidata":"https://www.wikidata.org/wiki/Q568494","display_name":"Single sign-on","level":3,"score":0.6150189638137817},{"id":"https://openalex.org/C2780385302","wikidata":"https://www.wikidata.org/wiki/Q367158","display_name":"Protocol (science)","level":3,"score":0.5386857986450195},{"id":"https://openalex.org/C21564112","wikidata":"https://www.wikidata.org/wiki/Q4825885","display_name":"Authentication protocol","level":3,"score":0.4967196583747864},{"id":"https://openalex.org/C2778355321","wikidata":"https://www.wikidata.org/wiki/Q17079427","display_name":"Identity (music)","level":2,"score":0.48864322900772095},{"id":"https://openalex.org/C77618280","wikidata":"https://www.wikidata.org/wiki/Q1155772","display_name":"Scheme (mathematics)","level":2,"score":0.4809540808200836},{"id":"https://openalex.org/C24890656","wikidata":"https://www.wikidata.org/wiki/Q82811","display_name":"Acoustics","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C142724271","wikidata":"https://www.wikidata.org/wiki/Q7208","display_name":"Pathology","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.0},{"id":"https://openalex.org/C204787440","wikidata":"https://www.wikidata.org/wiki/Q188504","display_name":"Alternative medicine","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.56553/popets-2023-0100","is_oa":true,"landing_page_url":"https://doi.org/10.56553/popets-2023-0100","pdf_url":"https://petsymposium.org/popets/2023/popets-2023-0100.pdf","source":{"id":"https://openalex.org/S4210183172","display_name":"Proceedings on Privacy Enhancing Technologies","issn_l":"2299-0984","issn":["2299-0984"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320322","host_organization_name":"De Gruyter Open","host_organization_lineage":["https://openalex.org/P4310320322","https://openalex.org/P4310313990"],"host_organization_lineage_names":["De Gruyter Open","De Gruyter"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings on Privacy Enhancing Technologies","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.56553/popets-2023-0100","is_oa":true,"landing_page_url":"https://doi.org/10.56553/popets-2023-0100","pdf_url":"https://petsymposium.org/popets/2023/popets-2023-0100.pdf","source":{"id":"https://openalex.org/S4210183172","display_name":"Proceedings on Privacy Enhancing Technologies","issn_l":"2299-0984","issn":["2299-0984"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320322","host_organization_name":"De Gruyter Open","host_organization_lineage":["https://openalex.org/P4310320322","https://openalex.org/P4310313990"],"host_organization_lineage_names":["De Gruyter Open","De Gruyter"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings on Privacy Enhancing Technologies","raw_type":"journal-article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.4699999988079071}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4385522578.pdf"},"referenced_works_count":31,"referenced_works":["https://openalex.org/W1520146006","https://openalex.org/W1528195422","https://openalex.org/W1548963432","https://openalex.org/W1589034595","https://openalex.org/W1589205472","https://openalex.org/W1607188293","https://openalex.org/W1773518014","https://openalex.org/W1784881995","https://openalex.org/W1885156594","https://openalex.org/W1931152882","https://openalex.org/W2040407914","https://openalex.org/W2053070160","https://openalex.org/W2054702684","https://openalex.org/W2104648615","https://openalex.org/W2112995928","https://openalex.org/W2130056156","https://openalex.org/W2167841397","https://openalex.org/W2331705295","https://openalex.org/W2400148870","https://openalex.org/W2539042641","https://openalex.org/W2540310736","https://openalex.org/W2584183247","https://openalex.org/W2765667105","https://openalex.org/W2891698757","https://openalex.org/W3092407060","https://openalex.org/W3095887112","https://openalex.org/W3096870392","https://openalex.org/W3135799757","https://openalex.org/W3164072627","https://openalex.org/W4237810618","https://openalex.org/W4254697110"],"related_works":["https://openalex.org/W2392755385","https://openalex.org/W2364108391","https://openalex.org/W4319777932","https://openalex.org/W2086663091","https://openalex.org/W2354590300","https://openalex.org/W2213995339","https://openalex.org/W2137529864","https://openalex.org/W2809905916","https://openalex.org/W4292509751","https://openalex.org/W2802209085"],"abstract_inverted_index":{"OpenID":[0],"Connect":[1],"(OIDC)":[2],"is":[3,29,99,116,129,170],"a":[4,111,134,159,190],"Single":[5],"Sign-On":[6],"(SSO)":[7],"protocol":[8,48],"that":[9,84,103],"allows":[10],"users":[11,104],"to":[12,14,93,101,119,150,158],"authenticate":[13],"various":[15],"Relying":[16],"Parties":[17],"(RPs)":[18],"via":[19],"an":[20,185,201],"Identity":[21],"Provider":[22],"(IdP).":[23],"The":[24,144],"main":[25],"drawback":[26],"of":[27,32,50,167,183,203],"SSO":[28],"its":[30,148],"lack":[31],"privacy,":[33,61],"as":[34,62],"the":[35,38,54,70,94,113,123,141,177],"IdP":[36,71,145],"learns":[37],"RP\u2019s":[39],"identity":[40],"at":[41],"each":[42,155],"user\u2019s":[43],"login.":[44],"OIDC":[45,128],"supports":[46],"several":[47],"flows,":[49],"which":[51,127,168,172],"only":[52,105],"one,":[53],"Implicit":[55,114,142,187],"Flow,":[56,188],"gives":[57],"hope":[58],"for":[59,79],"any":[60],"it":[63],"does":[64],"not":[65],"require":[66],"direct":[67],"communication":[68],"between":[69],"and":[72,90,153,162,180,198],"RP.":[73,173],"This":[74,131],"design":[75],"was":[76],"initially":[77],"intended":[78],"RPs":[80,152],"with":[81],"technical":[82],"limitations":[83],"prevent":[85],"them":[86],"from":[87,122,194],"storing":[88],"credentials":[89],"thus":[91],"authenticating":[92],"IdP.":[95],"However,":[96],"RP":[97,138,163],"authentication":[98,139,156],"crucial":[100],"ensure":[102],"access":[106],"properly":[107],"registered":[108],"RPs.":[109],"As":[110],"result,":[112],"Flow":[115],"being":[117],"discussed":[118],"be":[120],"excluded":[121],"OAuth":[124],"specification":[125],"on":[126,200],"based.":[130],"paper":[132],"demonstrates":[133],"privacy-preserving":[135],"approach":[136],"incorporating":[137],"into":[140],"Flow.":[143],"can":[146],"restrict":[147],"service":[149],"authenticated":[151,186],"tie":[154],"token":[157],"specific":[160],"user":[161,169],"without":[164],"acquiring":[165],"knowledge":[166],"accessing":[171],"We":[174],"formally":[175],"define":[176],"desired":[178],"security":[179],"privacy":[181],"properties":[182],"such":[184],"propose":[189],"provably":[191],"secure":[192],"construction":[193],"generic":[195],"building":[196],"blocks,":[197],"report":[199],"implementation":[202],"our":[204],"scheme":[205]},"counts_by_year":[{"year":2025,"cited_by_count":4},{"year":2024,"cited_by_count":2}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
