• DocumentCode
    1726838
  • Title

    BPVrfy: Hybrid Cryptographic Scheme Based -- Federate Identity Attributes Verification Model for Business Processes

  • Author

    Guo, Nan ; Gao, Tianhan ; Zhang, Bin

  • Author_Institution
    Coll. of Inf. Sci. & Eng., Northeastern Univ., Shenyang, China
  • fYear
    2012
  • Firstpage
    417
  • Lastpage
    424
  • Abstract
    It is important that during the execution of a business process built from composable Web services from multiple domains, the component service be able to verify the identity of the user to check it has the required permissions for accessing the services, while at the same time identity attributes need to be protected properly as they can be target of attacks. In such context, we propose a privacy-preserved multi-domain identity attributes verification model BPVrfy. It extends federate identity management with support for multiple identity verification policies and privacy enhancement. Identity attributes verification process is partitioned into three sub-procedures consisting of attribute provision, federation enrollment and attributes transfer, and then a series of protocols based on cryptographic schemes is proposed respectively. BPVrfy adopts Perdersen Commitment, Zero-Knowledge Proof of Knowledge, BGLS Aggregate Signature and Certificate-Based Signature (CBS) cryptographic schemes together to give a privacy-preserved federate identity attributes verification solution for multi-domain Web services-based business processes.
  • Keywords
    Web services; business data processing; cryptographic protocols; data privacy; digital signatures; formal verification; BGLS aggregate signature; BPVrfy; CBS; Perdersen commitment; Web services; attribute provision; attributes transfer; business process; certificate-based signature cryptographic schemes; cryptographic protocol schemes; federate identity attributes verification model; federate identity management; federation enrollment; hybrid cryptographic scheme; multiple identity verification policies; privacy enhancement; privacy-preserved multidomain identity attributes verification model; zero-knowledge proof; Aggregates; Authentication; Educational institutions; Protocols; Public key; Risk management; BGLS Aggregate Signature; Certificate-Based Signature; Zero-Knowledge Proof of Knowledge; business processes; identity attributes verification;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2012 Seventh International Conference on
  • Conference_Location
    Prague
  • Print_ISBN
    978-1-4673-2244-7
  • Type

    conf

  • DOI
    10.1109/ARES.2012.65
  • Filename
    6329213