Blue Theme Orange Theme Green Theme Red Theme
 
6 Months Free & No Setup Fees ASP.NET Hosting!
Home | Forums | ASP.NET 2.0 Tutorials | Web Services | How Do I...? | Class Browser | WPF Quick Starts | Advertise with Us
 | Consulting  
Submit an Article Submit a Blog 
 Jump to
Skip Navigation Links
TechnologyExpand Technology
WebsiteExpand Website
6 Months Free & No Setup Fees ASP.NET Hosting!
Search :       Advanced Search »
Home » .NET 3.0 » An introduction to Windows CardSpace

An introduction to Windows CardSpace

In this article I am going to show that, what is new Security mechanism in .NET 3.0, It named as Windows CardSpace.

Author Rank :
Page Views : 3198
Downloads : 0
Rating :
 Rate it
Level : Beginner
   Print Read/Post comments Post a comment  Similar Articles  
   Email to a friend  Bookmark  Author's other articles  
 
6 Months Free & No Setup Fees ASP.NET Hosting!
Become a Sponsor
Become a Sponsor
 Tag Cloud
 Latest Jobs
More ... 
 Latest Interview Questions
More ... 

In .NET 3.0, there are 4 new technologies. One of them is Windows CardSpace.
 

Windows CardSpace is a Microsoft .NET Framework version 3.0 (WinFX) component that provides the consistent user experience required by the identity metasystem. Specially Windows CardSpace works to protect the user identity. Windows CardSpace provides the security to our ASP.NET application.
 

Windows CardSpace basically a digital identity. In networked world-identity is currently a much more muddled thing.
 

The Windows CardSpace Provides four aspects : 
 

  1. It support any digital identity system
  2. Consistent user control of digital identity
  3. Replacement of password-based Web login
  4. On remote application it improves the user confidence

Windows CardSpace Support any digital Identity 

 

Here there can be multiple identity, comes from different sources. In an identity there can be three parts. A Window CardSpace will support any digital identity. The three parts of an identity can be:
 

  • User
  • A provider which provides the Identity
  • Relying Party 

A user is a person, who will be identified. User will hold the identity. This identity will provided by an identity provider. Relying parties are  entities relying on digital identities for, say, authentication such as a web site or an online service.

Consistent user control of digital identity

To identify a user all application built to use CardSpace will use the exact same mechanism for working with digital identities, presenting them to users through the exact same interface. Because user have a consistent way to use their digital identities. If user does not use this consistent way, then there may be error. If user wants more security for his individual information then he can use personal identification numbers (PINs). It's worth pointing out that providing a consistent mechanism for users to select which digital identity to use is an intrinsic part of the identity metasystem. To achieve this, CardSpace implements an intuitive user interface for working with digital identities.

Replacement of password-based Web login

To identify the authorized user today on internet there is most useable way to provide a username. There is a password associated with every username. The user identifies by entering right username and password. Which site you are going to access, sometime they provide the username and password to you. Because sites that do this typically use SSL for communicating with your browser, this approach has been seen as reasonably secure. SSL ensures that the entire communication is encrypted, and therefore attackers can't steal your password by listening in on the communication. To improve the security of Web login in general, CardSpace allows replacing password-based Web login with a stronger mechanism. CardSpace includes a self-issued identity provider. Information cards created by the self-issued identity provider can contain only basic information, such as the user's name, postal address, e-mail address, and phone number. When a user chooses to submit one of these cards to a relying party, the self-issued identity provider on that user's system generates a SAML token containing the information the user has placed in this card. 

The self-issued identity provider also generates a public/private key pair, signing the security token with the private key. This security token contains a timestamp to prevent the phisher from reusing or copying it. After this the application sends the signed token  with its associated public key, to the relying party. The relying party can use the public key to validate the security token's digital signature. To make it impossible for relying parties to get together and track a user's activities by comparing that user's public key, the self-issued identity provider creates a different key pair for every relying party that's accessed with this card.

It Improves user confidence in the identity of remote applications

By providing login control on site, user can feel some secure from phishing. But this is not 100% secure. From here the phisher can't see the user password, but the phisher can know other information. A phisher can make the site with their same logo and information like as in other site. Then here how users can sure that which site he is going to use is secure or not.

For handling with this problem requires two things:

 

  • A higher-assurance way for a website to prove its identity to users.
  • A consistent way for those users to learn what level of assurance a site is offering as proof of its identity, and then to make an explicit decision about whether to trust that site.  

What Information Cards Contain

 

In choosing digital identity the contents of information card helps the user.They also allow CardSpace to match a card to a relying party's requirements, and to acquire an appropriate security token from the identity provider that issued this card. To accomplish these two goals, every information card contains the following:

  • A file of JPEG or GIF with the image of the card that the user sees on his or her screen, along with the name of the card that's displayed to him or her.
  • A globally unique identifier (specified as a URI) created by the IdP. 
  • A URL for one or more endpoints at this identity provider that can be accessed to request a security token.
  • A URL identifying an endpoint at the identity provider from which its policy can be obtained. As described in the next section, this information also tells CardSpace how requests to the identity provider should be authenticated.
  • The date and time the information card was created.
  • In a card the most important thing to note that is there any information missing which is most required. Like as in a credit card, if we use it then there should we credit card number.

Comment Request!
Thank you for reading this post. Please post your feedback, question, or comments about this post Here.
Login to add your contents and source code to this article
 [Top] Rate this article
 
 About the author
 
Rahul Kumar Saxena
Rahul shows great interests in working with Microsoft technologies. He specializes in the implementation of DataBase & Graphics. His area of expertise includes: C#, ASP.NET,ADO.NET,Windows Forms & Web Services. He hails from background , Master's in Computer Application. With programming he loves photography, traveling and reading books.
(Talabpur*)
Looking for C# Consulting?
C# Consulting is founded in 2002 by the founders of C# Corner. Unlike a traditional consulting company, our consultants are well-known experts in .NET and many of them are MVPs, authors, and trainers. We specialize in Microsoft .NET development and utilize Agile Development and Extreme Programming practices to provide fast pace quick turnaround results. Our software development model is a mix of Agile Development, traditional SDLC, and Waterfall models.
Click here to learn more about C# Consulting.
 
Introducing MaxV - one click. infinite control. Hyper-V Hosting from MaximumASP.
Finally – a virtual platform that delivers next-generation Windows Server 2008 Hyper-V virtualization technology from a managed hosting partner you can truly depend on. Visit www.maximumasp.com/max for a FREE 30 day trial. Hurry offer ends soon. Climb aboard the MaxV platform and take advantage of High Availability, Intelligent Monitoring, Recurrent Backups, and Scalability – with no hassle or hidden fees. As a managed hosting partner focused solely on Microsoft technologies since 2000, MaximumASP is uniquely qualified to provide the superior support that our business is built on. Unparalleled expertise with Microsoft technologies lead to working directly with Microsoft as first to offer IIS 7 and SQL 2008 betas in a hosted environment; partnering in the Go Live Program for Hyper-V; and product co-launches built on WS 2008 with Hyper-V technology.
Dynamic PDF
ceTE software specializes in components for dynamic PDF generation and manipulation. The DynamicPDF™ product line allows you to dynamically generate PDF documents, merge PDF documents and new content to existing PDF documents from within your applications.
Nevron Chart for .NET 2010.1 Now Available
The leading .NET charting control now features PDF, Flash and Silverlight export, visualization of large datasets and more. Deliver true charting functionality to your BI, Scorecard, Presentation or Scientific apps. Download evaluation now.
ASP.NET 4 Hosting
Get 2 Months Free of ASP.NET Hosting for Only $4.95/month! Receive FREE MS SQL and MySQL Databases Including ASP.NET 4/3.5, MVC 3.0, Silverlight 4, Windows 2008/IIS 7.0 Plus FREE IIS 7 Modules. Host UNLIMITED ASP.NET Web Sites – Click Here!
 
 Post a Feedback, Comment, or Question about this article
Subject:
Comment:
Team Foundation Server Hosting
Become a Sponsor
 Comments
Team Foundation Server Hosting
 © 2012  contents copyright of their authors. Rest everything copyright Mindcracker. All rights reserved.