%0 Journal Article %A HE Xudong %A LU Jintian %A MENG Bo %A YAO Lili %T Improvement of OpenID Connect protocol and its security analysis %D 2017 %R 10.11772/j.issn.1001-9081.2017.05.1347 %J Journal of Computer Applications %P 1347-1352 %V 37 %N 5 %X OpenID Connect protocol is widely used in identity authentication field and is one of the newest single sign-on protocols. In this paper, the digital signature and asymmetric encryption were used to improve OpenID connect protocol. The secrecy and authentication of the improved protocol were focused. And then the improved OpenID connect protocol was formalized with the applied PI calculus in the symbolic model, next the secrecy was modeled by query and the authentication was modeled by non-injective relations to test the secrecy and authentication of improved OpenID Connect protocol. Finally the formal model of the OpenID Connect protocol was transformed into the input of the automatic tool ProVerif based on symbol model. The results indicate that the improved OpenID Connect protocol is authenticable and secret. %U http://www.joca.cn/EN/10.11772/j.issn.1001-9081.2017.05.1347