• DocumentCode
    2234402
  • Title

    User requirement model for federated identities threats

  • Author

    Ahmad, Zubair ; Manan, Jamalul-lail Ab ; Sulaiman, Suziah

  • Author_Institution
    Cyber Security Cluster, MIMOS Berhad, Kuala Lumpur, Malaysia
  • Volume
    6
  • fYear
    2010
  • fDate
    20-22 Aug. 2010
  • Abstract
    Federated identity management system interconnects distributed island of identity management systems with federated identity standards with single sign-on facility. In an open environment, such as those of a federated identity management system a user single sign-on credentials, can easily fall prey to identity theft, or unlawful information gathering. It may use either existing account or new account fraud. In this paper, we present scenarios related to identity theft, unlawful information gathering and tracking. We show the main issue of lack of platform trust in platforms involve in federated systems and discussed the consequences of respective threats on them. In an effort to present a holistic approach to handle security, trust and privacy, we propose a user requirement model involving these core issues for federated identities. These requirements include system trustworthiness, hardware protected key generations, usability, efficiency, identity information validity, privacy, accountability and system robustness. In our proposed model, Trusted Platform Module (TPM), is the fundamental component which ties and binds all communicating platforms together in authentication, verification and trustworthiness of the platform.
  • Keywords
    biometrics (access control); data privacy; formal verification; security of data; federated identity management system; federated identity threat; hardware protected key generation; identity information validity; identity theft; open environment; single sign on facility; system robustness; system trustworthiness; trusted platform module; unlawful information gathering; user requirement model; Authentication; Biological system modeling; Cryptography; Organizations; Resistance; Tracking; identification information; identity theft; platform trust; privacy; security; trusted platform module;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Computer Theory and Engineering (ICACTE), 2010 3rd International Conference on
  • Conference_Location
    Chengdu
  • ISSN
    2154-7491
  • Print_ISBN
    978-1-4244-6539-2
  • Type

    conf

  • DOI
    10.1109/ICACTE.2010.5579819
  • Filename
    5579819