• DocumentCode
    2129355
  • Title

    The Trusted Attribute Aggregation Service (TAAS) - Providing an Attribute Aggregation Layer for Federated Identity Management

  • Author

    Chadwick, David W. ; Inman, George

  • Author_Institution
    Sch. of Comput., Univ. of Kent, Canterbury, UK
  • fYear
    2013
  • fDate
    2-6 Sept. 2013
  • Firstpage
    285
  • Lastpage
    290
  • Abstract
    We describe a web based federated identity management system loosely based on the user centric Windows Card Space model. Unlike Card Space that relies on a fat desktop client (the identity selector) in which the user can only select a single card per session, our model uses a standard web browser with a simple plugin that connects to a trusted attribute aggregation web service (TAAS). TAAS supports the aggregation of attributes from multiple identity providers (IdPs) and allows the user to select multiple single attribute "cards" in a session, which more accurately reflects real life in which users may present several plastic cards and self-asserted attributes in a single session. Privacy protection, user consent, and ease of use are critical success factors. Consequently TAAS does not know who the user is, the user consents by selecting the attributes she wants to release, and she only needs to authenticate to a single IdP even though attributes may be aggregated from multiple IdPs. The system does not limit the authentication mechanisms that can be used, and it protects the user from phishing attacks by malicious SPs.
  • Keywords
    Web services; client-server systems; computer crime; data privacy; message authentication; online front-ends; trusted computing; TAAS; Web based federated identity management system; Windows card space model; attribute aggregation layer; authentication mechanisms; critical success factors; desktop client; identity selector; malicious SP; multiple identity providers; multiple single attribute; phishing attacks; plastic cards; plugin; privacy protection; self-asserted attributes; standard Web browser; trusted attribute aggregation Web service; trusted attribute aggregation service; user consent; Authentication; Authorization; Browsers; Cryptography; Protocols; Standards; attribute aggregation; identity management;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
  • Conference_Location
    Regensburg
  • Type

    conf

  • DOI
    10.1109/ARES.2013.38
  • Filename
    6657254