Enabling Trust in Single Sign-On Using DNS Based Authentication of Named Entities

Usman Aijaz N 1,* Nikita Mittal 2 Mohammed Misbahuddin 3 A Syed Mustafa 1

1. VTU, HKBKCSERC Bangalore560045, India

2. Reliance Jio Infocomm Ltd, Mumbai, India.

3. CDAC (Centre for Development of Advanced Computing)/ACTS & BD Bangalore- 560 100

* Corresponding author.

DOI: https://doi.org/10.5815/ijwmt.2022.01.05

Received: 24 Aug. 2021 / Revised: 23 Sep. 2021 / Accepted: 18 Oct. 2021 / Published: 8 Feb. 2022

DNS, DNSSEC, DANE, SAML, TLSA, IP Address, Digital Certificates


Single Sign-On (SSO) allows the client to access multiple partner e-services through a single login session. SSO is convenient for the users as the user neither needs to set multiple login credentials nor login separately for individual services every time. SSO (single sign-on) authentication is a password-authentication approach that permits end users to login into multiple systems and websites with a single set of login credentials. SSO authentication is mainly useful for IT organizations that consist of many different commercial applications. The outstanding feature of SSO is that it gives organizations centralized control of their systems by giving different levels of access to each individual. It reduces password fatigue and increases security because users only need to remember a single username/password that grants them access to multiple systems. However, the Single Sign-on poses risks related to a single point of attack which may lead to a path for cybercrimes. This paper proposes a trust model to increase the security of Single Sign-on systems against the vulnerabilities discussed in the subsequent sections. The proposed Trust model is named as DANE-based Trust Plugin (DTP) which acts as an added security layer over DNS Based Authentication of Named entities(DANE). The DTP proposes the modified SAML XML schema which enables the DTP to counter the attacks.

Usman Aijaz N, Nikita Mittal, Mohammed Misbahuddin, A Syed Mustafa, " Enabling Trust in Single Sign-On Using DNS Based Authentication of Named Entities", International Journal of Wireless and Microwave Technologies(IJWMT), Vol.12, No.1, pp. 41-53, 2022. DOI: 10.5815/ijwmt.2022.01.05


