{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T02:20:49Z","timestamp":1761963649514,"version":"build-2065373602"},"publisher-location":"Berlin, Heidelberg","reference-count":22,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642173028"},{"type":"electronic","value":"9783642173035"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-3-642-17303-5_6","type":"book-chapter","created":{"date-parts":[[2010,11,12]],"date-time":"2010-11-12T14:43:01Z","timestamp":1289572981000},"page":"73-84","source":"Crossref","is-referenced-by-count":18,"title":["A Security Analysis of OpenID"],"prefix":"10.1007","author":[{"given":"Bart","family":"van Delft","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martijn","family":"Oostdijk","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"6_CR1","doi-asserted-by":"crossref","unstructured":"Adida, B.: BeamAuth: Two-Factor Web Authentication with a Bookmark. In: ACM Conference on Computer and Communications Security, pp. 48\u201357 (2007)","DOI":"10.1145\/1315245.1315253"},{"key":"6_CR2","unstructured":"Arnott, A.: OpenID Association Spoofing. blog.nerbank.net (March 2009), http:\/\/blog.nerdbank.net\/2009\/03\/openid-association-poisoning.html"},{"key":"6_CR3","doi-asserted-by":"crossref","unstructured":"Bradner, S.: Key words for use in RFCs to Indicate Requirement Levels. RFC 2119 (1997)","DOI":"10.17487\/rfc2119"},{"key":"6_CR4","doi-asserted-by":"publisher","first-page":"644","DOI":"10.1109\/TIT.1976.1055638","volume":"IT-22","author":"W. Diffie","year":"1976","unstructured":"Diffie, W., Hellman, M.E.: New directions in Cryptography. IEEE Transactions on Information Theory\u00a0IT-22, 644\u2013654 (1976)","journal-title":"IEEE Transactions on Information Theory"},{"key":"6_CR5","unstructured":"Drebes, L.: Relying Party Stats as of Jan 1st, 2009. JanRain Blog (January 2009), http:\/\/blog.janrain.com\/2009\/01\/relying-party-stats-as-of-jan-1st-2008.html"},{"key":"6_CR6","unstructured":"Hansen, R., Grossman, J.: Clickjacking (September 2008), http:\/\/www.sectheory.com\/clickjacking.htm"},{"key":"6_CR7","unstructured":"Hughes, J., Cantor, S., Hodges, J., Hirsch, F., Mishra, P., Philpott, R., Maler, E.: Profiles for the OASIS Securit Assertion Markup Language (SAML) V2.0 (March 2005), http:\/\/docs.oasis-open.org\/security\/saml\/v2.0\/"},{"key":"6_CR8","doi-asserted-by":"publisher","first-page":"1608","DOI":"10.1109\/ICACT.2008.4494089","volume-title":"2008 10th International Conference on Advanced Communication Technology, Gangwon-Do, South Korea","author":"H.-K. Oh","year":"2008","unstructured":"Oh, H.-K., Jin, S.-H.: The security limitations of SSO in OpenID. In: 2008 10th International Conference on Advanced Communication Technology, Gangwon-Do, South Korea, Piscataway, NJ, USA, February 17-20, pp. 1608\u20131611. IEEE, Los Alamitos (2008)"},{"key":"6_CR9","unstructured":"Jain, A., Hodges, J.: Openid review (November 2009), https:\/\/sites.google.com\/site\/openidreview\/"},{"key":"6_CR10","unstructured":"Jain, A., Nash, A., Hodges, J.: OpenID Security Issues. Presentation PayPal Information Risk Management (November 2009)"},{"key":"6_CR11","unstructured":"Lawrence, K., Kaer, C.: WS-Trust 1.4 OASIS Editor Draft (February 2008), http:\/\/docs.oasis-open.org\/ws-sx\/ws-trust\/200802\/ws-trust-1.4-ed-01.html"},{"key":"6_CR12","unstructured":"Lindholm, A.: Security Evaluation of the OpenID Protocol. Master\u2019s thesis, Sveriges St\u00f6rsta Tekniska Universitet, Sweden (2009)"},{"key":"6_CR13","unstructured":"McBride, T., Silver, D., Tebo, M., Louden, C., Bradley, J.: Federal Identity, Credentialing, and Access Management - OpenID 2.0 Profile. Release Candidate 1.0.1 (November 2009), http:\/\/www.idmanagement.gov\/documents\/ICAM_OpenID20Profile.pdf"},{"key":"6_CR14","unstructured":"Messina, C.: OpenID Phising Brainstorm (December 2008), http:\/\/wiki.openid.net , http:\/\/wiki.openid.net\/OpenID_Phishing_Brainstorm"},{"key":"6_CR15","unstructured":"Anonymous (most\u00a0likely Ashish\u00a0Jain and Jeff Hodges) (2009), https:\/\/sites.google.com\/site\/openidreview\/"},{"key":"6_CR16","unstructured":"Nanda, A.: Identity Selector Interoperability Profile V1.0 (2007)"},{"key":"6_CR17","unstructured":"oauth.net. OAuth Core 1.0 Revision A (June 2009), http:\/\/oauth.net\/core\/1.0a\/"},{"key":"6_CR18","unstructured":"Office of\u00a0Management and Budget (OMB). E-Authentication Guidance for Federal Agencies, Memorandum M-04-04 (December 2003), http:\/\/www.whitehouse.gov\/omb\/memoranda\/fy04\/m04-04.pdf"},{"key":"6_CR19","unstructured":"openid.net. OpenID Authentication 2.0 - Final (December 2007), http:\/\/openid.net\/specs\/openid-authentication-2_0.html"},{"key":"6_CR20","doi-asserted-by":"crossref","unstructured":"Recordon, D., Reed, D.: OpenID 2.0: A platform for User-Centric Identity Management. In: Conference on Computer and Communications Security Proceedings of the Second ACM Workshop on Digital Identity Management, Alexandria, Verginia, USA, pp. 11\u201316 (2006)","DOI":"10.1145\/1179529.1179532"},{"key":"6_CR21","unstructured":"Tom, A., Arnott, A.: OpenID Security Best Practices. openid.net (July 2009), http:\/\/wiki.openid.net\/OpenID-Security-Best-Practices"},{"key":"6_CR22","unstructured":"Tsyrklevich, E., Tsyrklevich, V.: Single Sign-On for the Internet: A Security Story. In: BlackHat USA (2007)"}],"container-title":["IFIP Advances in Information and Communication Technology","Policies and Research in Identity Management"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-17303-5_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,6]],"date-time":"2019-06-06T07:37:27Z","timestamp":1559806647000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-17303-5_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010]]},"ISBN":["9783642173028","9783642173035"],"references-count":22,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-17303-5_6","relation":{},"ISSN":["1868-4238","1861-2288"],"issn-type":[{"type":"print","value":"1868-4238"},{"type":"electronic","value":"1861-2288"}],"subject":[],"published":{"date-parts":[[2010]]}}}