BEGIN:VCALENDAR
VERSION:2.0
PRODID:IEEE vTools.Events//EN
CALSCALE:GREGORIAN
BEGIN:VTIMEZONE
TZID:America/New_York
BEGIN:DAYLIGHT
DTSTART:20250309T030000
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:EDT
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251102T010000
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:EST
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTAMP:20250502T054240Z
UID:37C38F38-09E9-4A02-B994-0F0060B74540
DTSTART;TZID=America/New_York:20250501T174500
DTEND;TZID=America/New_York:20250501T200000
DESCRIPTION:The Northern Virginia and Washington Joint Computer Society Cha
 pter will host Ethan Heilman at the MLK Jr. Memorial Library for a virtual
  presentation on his research in authentication protocols for distributed 
 systems with OpenPubKey. Food and beverages will be available at the talk.
 \n\nOpenPubkey makes a client-side modification to OpenID Connect so that 
 an ID Token issued by an OpenID Provider commits to a user held public key
 . This transforms an ID Token into a certificate that cryptographically bi
 nds an OpenID Connect identity to a public key. The user can then sign mes
 sages with their signing key and these signatures can be authenticated and
  attributed to the user’s OpenID Connect identity. This allows OpenPubke
 y to upgrade OpenID Connect from Bearer Authentication to Proof-of-Possess
 ion\, eliminating trust assumptions in OpenID Connect and defeating entire
  categories of attacks present in OpenID Connect. OpenPubkey was designed 
 to satisfy a decade-long need for this functionality. Prior to OpenPubkey\
 , OpenID Connect did not have a secure way for users to sign statements un
 der their OpenID identities.\n\nOpenPubkey is transparent to users and Ope
 nID Providers. An OpenID Provider can not even determine that OpenPubkey i
 s being used. This makes OpenPubkey fully compatible with existing OpenID 
 Providers. OpenPubkey does not add new trusted parties to OpenID Connect a
 nd reduces preexisting trust assumptions. If used in tandem with our MFA-c
 osigner\, OpenPubkey can maintain security even against a malicious OpenID
  Provider (the most trusted party in OpenID Connect).\n\nOpenPubkey is cur
 rently used in opkssh which allows SSH access management via identities li
 ke alice@example.com instead of long-lived keys. It does not replace OpenS
 SH\, but rather generates ssh public keys and configures sshd to verify th
 e ssh keys with OpenPubkey.\n\nIn this talk\, Ethan Heilman will be presen
 ting virtually and we have reserved room 401-G for anyone interested in vi
 ewing the talk at the MLK Jr. Memorial Library where they can ask Ethan qu
 estions on OpenPubkey\, and network with their fellow IEEE members. The ML
 K Jr. Memorial Library is conveniently located near two Metro stations\, b
 etween the Metro Center and Gallery Place-Chinatown Stations. The conferen
 ce room is located on the 4th floor of the library in the Conference Cente
 r.\n\nSpeaker(s): \, Ethan Heilman\n\nAgenda: \n5:45 PM Set Up and Introdu
 ctions\n\n6:00 PM - 7:30 PM OpenPubKey Talk\n\n7:30 PM - 8:00 PM Discussio
 n\n\nRoom: 401-G\, Bldg: Martin Luther King Jr. Memorial Library\, 901 G S
 t. NW\, Washington\, District of Columbia\, United States\, 20005\, Virtua
 l: https://events.vtools.ieee.org/m/481927
LOCATION:Room: 401-G\, Bldg: Martin Luther King Jr. Memorial Library\, 901 
 G St. NW\, Washington\, District of Columbia\, United States\, 20005\, Vir
 tual: https://events.vtools.ieee.org/m/481927
ORGANIZER:wdblair@ieee.org
SEQUENCE:17
SUMMARY:OpenPubkey: Augmenting OpenID Connect with User Held Signing Keys
URL;VALUE=URI:https://events.vtools.ieee.org/m/481927
X-ALT-DESC:Description: &lt;br /&gt;&lt;div dir=&quot;auto&quot;&gt;The Northern Virginia and Was
 hington Joint Computer Society Chapter will host Ethan Heilman at the MLK 
 Jr. Memorial Library for a virtual presentation on his research in authent
 ication protocols for distributed systems with OpenPubKey. Food and bevera
 ges will be available at the talk.&lt;/div&gt;\n&lt;div dir=&quot;auto&quot;&gt;&amp;nbsp\;&lt;/div&gt;\n&lt;
 div dir=&quot;auto&quot;&gt;OpenPubkey makes a client-side modification to OpenID Conne
 ct so that an ID Token issued by an OpenID Provider commits to a user held
  public key. This transforms an ID Token into a certificate that cryptogra
 phically binds an OpenID Connect identity to a public key. The user can th
 en sign messages with their signing key and these signatures can be authen
 ticated and attributed to the user&amp;rsquo\;s OpenID Connect identity. This 
 allows OpenPubkey to upgrade OpenID Connect from Bearer Authentication to 
 Proof-of-Possession\, eliminating trust assumptions in OpenID Connect and 
 defeating entire categories of attacks present in OpenID Connect. OpenPubk
 ey was designed to satisfy a decade-long need for this functionality. Prio
 r to OpenPubkey\, OpenID Connect did not have a secure way for users to si
 gn statements under their OpenID identities.&lt;/div&gt;\n&lt;div dir=&quot;auto&quot;&gt;&amp;nbsp\
 ;&lt;/div&gt;\n&lt;div dir=&quot;auto&quot;&gt;OpenPubkey is transparent to users and OpenID Pro
 viders. An OpenID Provider can not even determine that OpenPubkey is being
  used. This makes OpenPubkey fully compatible with existing OpenID Provide
 rs. OpenPubkey does not add new trusted parties to OpenID Connect and redu
 ces preexisting trust assumptions. If used in tandem with our MFA-cosigner
 \, OpenPubkey can maintain security even against a malicious OpenID Provid
 er (the most trusted party in OpenID Connect).&lt;/div&gt;\n&lt;div dir=&quot;auto&quot;&gt;&amp;nbs
 p\;&lt;/div&gt;\n&lt;div dir=&quot;auto&quot;&gt;OpenPubkey is currently used in opkssh which al
 lows SSH access management via identities like &lt;a href=&quot;mailto:alice@examp
 le.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer noreferrer&quot;&gt;alice@example
 .com&lt;/a&gt; instead of long-lived keys. It does not replace OpenSSH\, but rat
 her generates ssh public keys and configures sshd to verify the ssh keys w
 ith OpenPubkey.&lt;/div&gt;\n&lt;div dir=&quot;auto&quot;&gt;&amp;nbsp\;&lt;/div&gt;\n&lt;div dir=&quot;auto&quot;&gt;In t
 his talk\, Ethan Heilman will be presenting virtually and we have reserved
  room 401-G for anyone interested in viewing the talk at the MLK Jr. Memor
 ial Library where they can ask Ethan questions on OpenPubkey\, and network
  with their fellow IEEE members. The MLK Jr. Memorial Library is convenien
 tly located near two Metro stations\, between the Metro Center and Gallery
  Place-Chinatown Stations. The conference room is located on the 4th floor
  of the library in the Conference Center.&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Agenda: &lt;br /&gt;&lt;
 p&gt;5:45 PM Set Up and Introductions&lt;/p&gt;\n&lt;p&gt;6:00 PM - 7:30 PM OpenPubKey Ta
 lk &amp;nbsp\;&lt;/p&gt;\n&lt;p&gt;7:30 PM - 8:00 PM &amp;nbsp\;Discussion&lt;/p&gt;
END:VEVENT
END:VCALENDAR

