• DocumentCode
    1827332
  • Title

    A reference model for Authentication and Authorisation Infrastructures respecting privacy and flexibility in b2c eCommerce

  • Author

    Schläger, Christian ; Nowey, Thomas ; Montenegro, Jose A.

  • Author_Institution
    Dept. of Inf. Syst., Regensburg Univ., Germany
  • fYear
    2006
  • fDate
    20-22 April 2006
  • Abstract
    Authentication and Authorisation Infrastructures (AAIs) are gaining momentum throughout the Internet. Solutions have been proposed for various scenarios among them academia, grid computing, company networks, and above all eCommerce applications. Products and concepts vary in architecture, security features, target group, and usability containing different strengths and weaknesses. In addition security needs have changed in communication and business processes. Security on the Internet is no longer defined as only security measures for an eCommerce provider against an untrustworthy customer but also vice versa. Consequently, privacy, data canniness, and security are demands in this area. The authors define criteria for an eCommerce provider federation using an AAI with a maximum of privacy and flexibility. The criteria is derived concentrating on b2c eCommerce applications fulfilling the demands. In addition to best practices found, XACML policies and an attribute infrastructure are deployed. Among the evaluated AAIs are Shibboleth, Microsoft Passport, the Liberty Alliance Framework, and PERMIS.
  • Keywords
    Internet; authorisation; data privacy; electronic commerce; message authentication; AAI; Authentication and Authorisation Infrastructures; Internet; Liberty Alliance Framework; Microsoft Passport; PERMIS; Shibboleth; XACML policies; b2c eCommerce applications; data canniness; data privacy; security measures; Authentication; Authorization; Companies; Computer architecture; Data security; Electronic commerce; Grid computing; Internet; Privacy; Usability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security, 2006. ARES 2006. The First International Conference on
  • Print_ISBN
    0-7695-2567-9
  • Type

    conf

  • DOI
    10.1109/ARES.2006.13
  • Filename
    1625377