Open-source Identity Federation with Shibboleth (submission to EUNIS’2006 for a long paper)

نویسنده

  • Pascal Aubry
چکیده

Single Sign-On is widely deployed in the French Education/Research community, especially CAS [1]. In addition to improving the security, it allows users to authenticate once and use several web applications, as long as the applications are proposed by their institution. New projects in France now encourage the cooperation between universities, making them share web resources (documents and applications). In the first part, we list these new usages: Opening local web resources to the members of other institutions, Manage an intranet for a geographically distributed population, Inside an establishment, extend SSO features to the propagation of user attributes, Manage the authentication of users at the frontier of institutions (ancient or future students for instance), From the portal of an institution, read electronic publications proposed by commercial partners. We show that Single Sign-On technologies are not sufficient to handle these new needs, and that multiplying the authentication databases is very time-consuming and obviously not scalable (cf figure 1).

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

GridShib and PERMIS Integration

This paper describes the results of our recent GridShibPERMIS project to provide policy driven role-based access control decision making to Grid jobs, in which the user’s attributes are provided by a Shibboleth Identity Provider (IdP). The goal of the project is to integrate the identity federation and attribute assignment functions of Shibboleth with the policy-based enforcement function offer...

متن کامل

Organising Federated Identity in Finnish Higher Education

Finnish higher education has been an early adopter of federated identity in Europe. The Finnish Haka federation is deploying Shibboleth, federating software by Internet2. This paper describes the federation as an organisational entity and explains how privacy issues are taken into account in its policy. Differences between the Haka federation and some other federations are pointed out. The main...

متن کامل

A Guanxi Shibboleth based Security Infrastructure for e-Social Science

An e-Social Science infrastructure generally has security requirements to protect their restricted resources or services. As a widely accepted authentication and authorization technology, Shibboleth supports the sharing of resources on interinstitutional federation. Guanxi is an open source implementation of the Shibboleth protocol and architecture. In this paper, we propose a security infrastr...

متن کامل

Federated Identity Management in Business-to-Business Outsourcing

While the outsourcing of IT services is a promising and cost-effective solution for many aspects of today’s information and communication infrastructures, it poses new management challenges in the area of authentication, autorization and accounting (AAA). Due to the demand of cross-organizational AAA, traditional Identity & Access Management is presently developing into Federated Identity Manag...

متن کامل

Security for Web Services: Standards and Research Issues

This chapter identifies the main security requirements for Web services and it describes how such security requirements are addressed by standards for Web services security recently developed or under development by various standardizations bodies. Standards are reviewed according to a conceptual framework that groups them by the main functionalities they provide. Standards that are covered inc...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006