Identity/AttachedServices/KeyServerProtocol: Difference between revisions

Jump to navigation Jump to search
add use-the-auth-token high-level picture
(add use-the-auth-token high-level picture)
Line 158: Line 158:


The client recomputes the MAC, compares it (throwing an error if it doesn't match), extracts the ciphertext, XORs it with the derived respXORkey, then returns the authToken value.
The client recomputes the MAC, compares it (throwing an error if it doesn't match), extracts the ciphertext, XORs it with the derived respXORkey, then returns the authToken value.
= After Login: Using the authToken =
After the authToken is acquired, the client can create a session and fetch the encryption keys. The high-level flow looks like this:
[[File:PICL-IdPAuth-session-start.png|Using the authToken]]


= Creating a Session =
= Creating a Session =
Confirmed users
471

edits

Navigation menu