Auth Srv
App Srv
CorSSO Protocol
S
N
0
1
Client generates key
pair (K
U
, k
U
),
identifies self
separately to each
authentication server
Acquires a partially
signed token
Combines partially
signed tokens into a
single token signed
by
1
says:
“
k
U
1
speaks
for U”
Policy P
0
says:
“
k
U
0
speaks
for U”
U
Principal