Title :
Trusted Computing based open environment user authentication model
Author :
Ahmad, Zubair ; Manan, Jamalul-lail Ab ; Sulaiman, Suziah
Author_Institution :
Cyber Security Cluster, MIMOS Berhad, Kuala Lumpur, Malaysia
Abstract :
In federated identity management systems identity providers authenticate users of its realm via single sign-on and forward authentication assertion as a response to the service provider´s requests. Secure single sign-on authentication is always a challenging task in an open environment such as in Internet. The risk associated with an open environment authentication and authorization are user credentials stealing via man-in-the-middle attack, user platform infected with virus or Trojan horse, identity provider and service provider collude with each others. We reviewed current technologies´ Kerberos, Liberty Alliance, OpenID and Windows Live ID. However, the existing systems have limitations and weaknesses such as presence of third parties, no platform trust, and a weak authentication mechanism. In this paper, we propose a single-sign-on authentication model for an open environment to combine the trusted module security and platform trust in federated user systems. This model excludes third party involvement in every transaction such as identity or authentication service provider. The user platform in this model plays a role of an identity provider or authentication service. The security and privacy analysis of the proposed model shows our model can achieve strong security, platform trust and enhanced privacy.
Keywords :
authorisation; computer viruses; data privacy; distributed databases; message authentication; authorization; federated identity management systems; man-in-the-middle attack; open environment user; privacy analysis; single-sign-on authentication model; trusted computing; trusted module security; user credentials stealing; virus; Authentication; Certification; Computational modeling; authentication; federated identity management system; single sign-on; trusted platform module;
Conference_Titel :
Advanced Computer Theory and Engineering (ICACTE), 2010 3rd International Conference on
Conference_Location :
Chengdu
Print_ISBN :
978-1-4244-6539-2
DOI :
10.1109/ICACTE.2010.5579171