OpenID

The OpenID logo

OpenID is an open standard and decentralized authentication protocol promoted by the non-profit OpenID Foundation. It allows users to be authenticated by co-operating sites (known as relying parties, or RP) using a third-party identity provider (IDP) service, eliminating the need for webmasters to provide their own ad hoc login systems, and allowing users to log in to multiple unrelated websites without having to have a separate identity and password for each.[1] Users create accounts by selecting an OpenID identity provider,[1] and then use those accounts to sign on to any website that accepts OpenID authentication. Several large organizations either issue or accept OpenIDs on their websites.[2]

The OpenID standard provides a framework for the communication that must take place between the identity provider and the OpenID acceptor (the "relying party").[3] An extension to the standard (the OpenID Attribute Exchange) facilitates the transfer of user attributes, such as name and gender, from the OpenID identity provider to the relying party (each relying party may request a different set of attributes, depending on its requirements).[4] The OpenID protocol does not rely on a central authority to authenticate a user's identity. Moreover, neither services nor the OpenID standard may mandate a specific means by which to authenticate users, allowing for approaches ranging from the common (such as passwords) to the novel (such as smart cards or biometrics).

The final version of OpenID is OpenID 2.0, finalized and published in December 2007.[5] The term OpenID may also refer to an identifier as specified in the OpenID standard; these identifiers take the form of a unique Uniform Resource Identifier (URI), and are managed by some "OpenID provider" that handles authentication.[1]

  1. ^ a b c Eldon, Eric (14 April 2009). "Single sign-on service OpenID getting more usage". venturebeat.com. Retrieved 25 April 2009.
  2. ^ "What is an OpenID?". 8 October 2007. Retrieved 19 June 2014.
  3. ^ "OpenID Authentication 2.0 specification – Final". Retrieved 24 October 2011.
  4. ^ "OpenID Attribute Exchange 1.0 – Final". Retrieved 24 October 2011.
  5. ^ "OpenID Authentication 2.0 - Final". 5 December 2007. Retrieved 18 May 2014.