DocumentCode
2604927
Title
Assurance in identity management systems
Author
Chehab, Maya I. ; Abdallah, Ali E.
Author_Institution
E-Security Res. Centre, London South Bank Univ., London, UK
fYear
2010
fDate
23-25 Aug. 2010
Firstpage
216
Lastpage
221
Abstract
Degree of identity assurance has been realized in several different approaches to authentication assurance frameworks; to become one of the parameters used in decision making about whether to grant or deny a service. However, current approaches do not look at diversity of authentication mechanisms, used for establishing the identity of a user, as an application to mitigate identity threats and consequently affects identity assurance in the authentication operation. This paper revisits the area of authentication assurance to present a framework for using identity assurance in the context of risk-based service provisioning. It demonstrates identity assurance in the authentication operation as being affected by the diversity of authentication mechanisms. By considering diversity in mechanisms, this framework gives service providers confidence that services are only restricted to users who have satisfied a certain degree of identity assurance, by going through a rigorous mechanism for establishing identity. Moreover, by giving a user different mechanisms to authenticate to different services, this work is useful for enabling users to separate between identities used for services accessing information of different levels of criticality.
Keywords
authorisation; decision making; risk management; authentication assurance; decision making; identity management system; risk based service provision; Authentication; Context; Encryption; Organizations; Public key;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Assurance and Security (IAS), 2010 Sixth International Conference on
Conference_Location
Atlanta, GA
Print_ISBN
978-1-4244-7407-3
Type
conf
DOI
10.1109/ISIAS.2010.5604073
Filename
5604073
Link To Document