DocumentCode
1886135
Title
A study on threat model for federated identities in federated identity management system
Author
Khattak, Zubair Ahmad ; Sulaiman, Suziah ; Manan, J.A.
Author_Institution
Dept. of Comput. Inf. Sci., Univ. Teknol. PETRONAS, Tronoh, Malaysia
Volume
2
fYear
2010
fDate
15-17 June 2010
Firstpage
618
Lastpage
623
Abstract
Federated Identity Management (FIM) based on standards allows and facilitates participating federated organizations to share users identity attributes, facilitate authentication and grant or deny service access requests. Using single sign-on facility users authenticates only once to home identity provider and logged into access successive service providing service providers within federation. User´s identity theft, misused of user identity information via single sign-on facility in identity providers and service providers, and trustworthiness of subject, identity providers and service providers are active concerns in federated identity management systems. In addition, we had explored trusted computing technology, which covers Trusted Platform Module security features such as Trusted Platform Module Identity, Integrity Measurement and Key certification as well as Trusted Network Connect. In this paper, we presented conceptual threat model for inter-domain web single sign-on in federate identity management system. For this, we set identity theft, misused of identity information, and trust relationship scenarios and in the end, we discussed how trusted computing technology use can effectively resolve identity theft, misused of identity information, and trust relationship concerns in federated identity management system.
Keywords
Internet; cryptography; message authentication; FIM; access successive service; authentication; deny service access requests; federated identity management system; federated organizations; home identity provider; identity theft; integrity measurement; inter-domain Web single sign-on; key certification; service providers; single sign-on facility; threat model; trust relationship; trusted computing technology; trusted network connect; trusted platform module identity; trusted platform module security features; user identity information; users identity attributes; Cryptography; Variable speed drives; federated identity management; identity theft; misused of identity information; trust relationship; trusted computing;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Technology (ITSim), 2010 International Symposium in
Conference_Location
Kuala Lumpur
ISSN
2155-897
Print_ISBN
978-1-4244-6715-0
Type
conf
DOI
10.1109/ITSIM.2010.5561611
Filename
5561611
Link To Document