Changes

Jump to: navigation, search

Identity/AttachedServices/KeyServerProtocol

260 bytes removed, 05:07, 1 August 2013
m
Login: Obtaining the authToken
This protocol starts by using key-stretching to transform the email+password into a "stretchedPW", then feeds this into an SRP protocol to get the authToken.
 
session key. It uses this session key to decrypt a bundle of encrypted data from the keyserver, resulting in three values: kA, wrap(kB), and the sessionToken. The stretchedPW is also used to derive the key that will decrypt wrap(kB) into the actual kB value.
[[File:PICL-IdPAuth-auth-start.png|IdP Auth Protocol]]
Confirm
471
edits

Navigation menu