An Architecture for Privacy-Aware Inter-domain Identity Management
نویسنده
چکیده
The management of service oriented architectures demands an efficient control of service users and their authorizations. Similar to structured cabling in LANs, Identity & Access Management systems have proven to be important components of organizations’ IT infrastructures. Yet, due to new management challenges such as virtual organizations, on-demand computing and the integration of third party services through composition, identity information has to be passed to external service providers; this decentralization inherently leads to interoperability and privacy issues, which existing management standards are not dealing with appropriately yet. We present an architecture, based on SAML, XACML and XSLT, which provides a tight integration of crossorganizational identity data transfer into the local provisioning business processes along with a policy-driven inter-domain privacy management system, and its implementation.
منابع مشابه
A privacy architecture for context-aware enterprise social networks
Context information is used to derive user profiles and social networks in an enterprise system called Instant Knowledge. This system requires privacy as well as conventional information security requirements. The privacy requirements include anonymity, unlinkability, unobservability and pseudonymity; these are designed to provide privacy by default to users of an Instant Knowledge service. A p...
متن کاملA Model for Privacy-enhanced Federated Identity Management
Identity federations operating in a business or consumer context need to prevent the collection of user data across trust service providers for legal and business case reasons. Legal reasons are given by data protection legislation such as [1]. Other reasons include business owners becoming increasingly aware of confidentiality risks that go beyond traditional information security, e.g., the nu...
متن کاملThe Architecture of a Privacy-Aware Access Control Decision Component
Today many interactions are carried out online through Web sites and e-services and often private and/or sensitive information is required by service providers. A growing concern related to this widespread diffusion of on-line applications that collect personal information is that users’ privacy is often poorly managed and sometimes abused. For instance, it is well known how personal informatio...
متن کاملSecurity in context-aware mobile business applications
The support of location computation on mobile devices (e.g. mobile phones, PDAs) has enabled the development of context-aware and especially locationaware applications (e.g. Restaurant Finder, Friend Finder) which are becoming the new trend for future software applications. However, fears regarding security and privacy are the biggest barriers against their success. Especially, mobile users are...
متن کاملTrust Management Model and Architecture for Context-Aware Service Platforms
The entities participating in a context-aware service platform need to establish and manage trust relationships in order to assert different trust aspects including identity provisioning, privacy enforcement, and context information provisioning. Current trust management models address these trust aspects individually when in fact they are dependent on each other. In this paper we identify and ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2005