Title :
BPVrfy: Hybrid Cryptographic Scheme Based -- Federate Identity Attributes Verification Model for Business Processes
Author :
Guo, Nan ; Gao, Tianhan ; Zhang, Bin
Author_Institution :
Coll. of Inf. Sci. & Eng., Northeastern Univ., Shenyang, China
Abstract :
It is important that during the execution of a business process built from composable Web services from multiple domains, the component service be able to verify the identity of the user to check it has the required permissions for accessing the services, while at the same time identity attributes need to be protected properly as they can be target of attacks. In such context, we propose a privacy-preserved multi-domain identity attributes verification model BPVrfy. It extends federate identity management with support for multiple identity verification policies and privacy enhancement. Identity attributes verification process is partitioned into three sub-procedures consisting of attribute provision, federation enrollment and attributes transfer, and then a series of protocols based on cryptographic schemes is proposed respectively. BPVrfy adopts Perdersen Commitment, Zero-Knowledge Proof of Knowledge, BGLS Aggregate Signature and Certificate-Based Signature (CBS) cryptographic schemes together to give a privacy-preserved federate identity attributes verification solution for multi-domain Web services-based business processes.
Keywords :
Web services; business data processing; cryptographic protocols; data privacy; digital signatures; formal verification; BGLS aggregate signature; BPVrfy; CBS; Perdersen commitment; Web services; attribute provision; attributes transfer; business process; certificate-based signature cryptographic schemes; cryptographic protocol schemes; federate identity attributes verification model; federate identity management; federation enrollment; hybrid cryptographic scheme; multiple identity verification policies; privacy enhancement; privacy-preserved multidomain identity attributes verification model; zero-knowledge proof; Aggregates; Authentication; Educational institutions; Protocols; Public key; Risk management; BGLS Aggregate Signature; Certificate-Based Signature; Zero-Knowledge Proof of Knowledge; business processes; identity attributes verification;
Conference_Titel :
Availability, Reliability and Security (ARES), 2012 Seventh International Conference on
Conference_Location :
Prague
Print_ISBN :
978-1-4673-2244-7
DOI :
10.1109/ARES.2012.65