The ES - LoA Project WP 1 Deliverable Using LoA to Achieve Risk - Based Access Control : A Study Report

نویسندگان

  • Aleksandra Nenadić
  • Ning Zhang
چکیده

Robust electronic authentication capable of reliably identifying remote entities (human users or software components) with a certain level of assurance in authentication strength is an important prerequisite to facilitate effective user authorisation and fine-grained access control in distributed systems. In a Federated Access Management environment, users are referred back to their home or affiliated institutions (playing the role of identity providers) for authentication, and subsequently gain access to resources provided by other federation members (i.e. service providers) through the use of attributes asserted by their respective IdPs. The separation of duties between identity providers (IdPs) and service providers (SPs) means that SPs no longer have control over the identity vetting procedures and authentication processes used to establish a user's identity. IdPs may employ dissimilar identity management policies, cross-checking procedures and authentication mechanisms, resulting in a spectrum of levels among which users are identified. More and more diverse resources are expected to join the federated environment, and they may have varying levels of sensitivity depending on their values and severity of consequences in an event of a security breach. SPs managing more sensitive resources may require a stronger form of user identification, while others having less valuable resources may not wish to subject their users to unnecessarily burdensome procedures. Increasing the level of confidence in identifying users may, on the one hand, enable more security conscious services to join a federation, but, on the other hand, inflate running costs and create a less user-friendly environment resulting in a reluctance of some providers of lower value resources to join the federation. Thus, there is a need for a more fine-grained approach to access control to replace the existing binary (grant-or-deny) solution where access control is achieved using the 'one-method-fits-all' approach regardless of the resource sensitivity and risk levels. One way to achieve the vision of fine-grained access control is to quantify the quality or strength of an authentication process in terms of an authentication Level of Assurance (LoA), and use the LoA value as a parameter for authorisation decision making. With this approach, assurance levels and costs in identity vetting and entity authentication can be linked to the values of the assets or risk levels in the accessed environment. The higher the value or sensitivity of the assets, the more formal and stricter the identity vetting process and, thus, a higher level of assurance in the underlying authentication service will be needed. …

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Defined Set of LoA Recommendations for the Use within the UK Education and Research Communities

The ES-LoA project, funded by the UK Joint Information Systems Committee (JISC) under its e-Infrastructure Security Programme, investigates current and future needs among UK research and education community for a more fine-grained access control, which allows service providers to take into account of the levels of confidence in identifying a remote entity requesting for service access. Such a f...

متن کامل

Overview: Report of a Scientific Working Group on Serious Adverse Events following Mectizan® treatment of onchocerciasis in Loa loa endemic areas.

This report reviews information on Serious Adverse Events (SAE), mainly Loa-encephalopathy, following treatment with ivermectin (Mectizan®, Merck, Sharpe & Dohme) for control of onchocerciasis carried out by the African Programme for Onchocerciasis Control (APOC), in areas where heavy microfilarial infections with Loa loa are coendemic with Onchocerca volvulus infections. It also endeavours to ...

متن کامل

Mapping the distribution of Loa loa in Cameroon in support of the African Programme for Onchocerciasis Control

BACKGROUND: Loa loa has recently emerged as a filarial worm of significant public health importance as a consequence of its impact on the African Programme for Onchocerciasis Control (APOC). Severe, sometimes fatal, encephalopathic reactions to ivermectin (the drug of choice for onchocerciasis control) have occurred in some individuals with high Loa loa microfilarial counts. Since high density ...

متن کامل

Encephalopathy Related to Ivermectin Treatment of Onchocerciasis in Loa loa Endemic Areas: Operational Considerations

Human onchocerciasis is a public health problem and an obstacle to socioeconomic development in endemic countries of Africa, Arabian Peninsula and South America (WHO, 1995). The community-directed treatment with ivermectin (CDTI) is the main strategy adopted by the African Programme for Onchocerciasis control (APOC). Severe adverse events with encephalopathy (SAEs) have been associated with mas...

متن کامل

Rapid assessment method for prevalence and intensity of Loa loa infection.

OBJECTIVE To assess the validity of observations on eye worm and Calabar swellings for the rapid assessment of the prevalence and intensity of loiasis at the community level. METHOD A total of 12895 individuals over the age of 15 years living in 102 communities in Cameroon and Nigeria took part in the study. A standardized questionnaire was administered to participants from whom finger-prick ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2007