• DocumentCode
    3193085
  • Title

    Integrating OpenID with proxy re-encryption to enhance privacy in cloud-based identity services

  • Author

    Nunez, David ; Agudo, I. ; Lopez, J.

  • Author_Institution
    Network Inf. & Comput. Security Lab., Univ. de Malaga, Malaga, Spain
  • fYear
    2012
  • fDate
    3-6 Dec. 2012
  • Firstpage
    241
  • Lastpage
    248
  • Abstract
    The inclusion of identity management in the cloud computing landscape represents a new business opportunity for providing what has been called Identity Management as a Service (IDaaS). Nevertheless, IDaaS introduces the same kind of problems regarding privacy and data confidentiality as other cloud services; on top of that, the nature of the outsourced information (users´ identity) is critical. Traditionally, cloud services (including IDaaS) rely only on SLAs and security policies to protect the data, but these measures have proven insufficient in some cases; recent research has employed advanced cryptographic mechanisms as an additional safeguard. Apart from this, there are several identity management schemes that could be used for realizing IDaaS systems in the cloud; among them, OpenID has gained crescent popularity because of its open and decentralized nature, which makes it a prime candidate for this task. In this paper we demonstrate how a privacy-preserving IDaaS system can be implemented using OpenID Attribute Exchange and a proxy re-encryption scheme. Our prototype enables an identity provider to serve attributes to other parties without being able to read their values. This proposal constitutes a novel contribution to both privacy and identity management fields. Finally, we discuss the performance and economical viability of our proposal.
  • Keywords
    cloud computing; cryptography; data privacy; IDaaS; OpenID attribute exchange; OpenID integration; SLA; cloud computing; cloud service; cloud-based identity service; cryptographic mechanism; data confidentiality; data privacy enhancement; data protection; decentralized nature; identity management as a service; identity provider; outsourced information; proxy re-encryption scheme; security policy; Authentication; Cloud computing; Encryption; Privacy; Proposals; Public key; OpenID; cloud computing; cryptography; encryption; identity management; privacy; proxy reencryption;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cloud Computing Technology and Science (CloudCom), 2012 IEEE 4th International Conference on
  • Conference_Location
    Taipei
  • Print_ISBN
    978-1-4673-4511-8
  • Electronic_ISBN
    978-1-4673-4509-5
  • Type

    conf

  • DOI
    10.1109/CloudCom.2012.6427551
  • Filename
    6427551