Title :
Group Management System for Federated Identities with Flow Control of Membership Information by Subjects
Author :
Nishimura, Takeshi ; Nakamura, Motonori ; Otani, Makoto ; Yamaji, Kazutsuna ; Sonehara, Noboru
Author_Institution :
R&D Center for Acad. Networks, Nat. Inst. of Inf., Tokyo, Japan
Abstract :
Federated identities are rapidly spreading, especially in the academic world. Some services in identity federations need ID groups to provide the collaborative work and/or access control based on contracts with groups. Some existing group management systems in identity federations can provide services with group membership information, but they lack support for contracts and flow control of the membership information. It is important that the group administrators can control the group membership information to avoid unintentional information disclosure. We propose the concept of Member Attribute Provider (mAP) with membership information control by group administrators and service administrators, which provides membership information of groups to services within an identity federation. We have made an implementation in Japanese academic access management federation called GakuNin, and make sure that it works properly with several production-level services.
Keywords :
authorisation; contracts; educational administrative data processing; groupware; information management; GakuNin; ID groups; Japanese academic access management federation; access control; collaborative work; contracts; federated identities; group administrators; group management system; group membership information; mAP; member attribute provider; membership information flow control; production-level services; service administrators; unintentional information disclosure avoidance; Access control; Authentication; Connectors; Contracts; Educational institutions; Organizations; Standards organizations; Implementation; Shibboleth; attribute provider; federated group management; identity federation;
Conference_Titel :
Computer Software and Applications Conference Workshops (COMPSACW), 2012 IEEE 36th Annual
Conference_Location :
Izmir
Print_ISBN :
978-1-4673-2714-5
Electronic_ISBN :
978-0-7695-4758-9
DOI :
10.1109/COMPSACW.2012.27