• DocumentCode
    3343196
  • Title

    Architectures for identity management

  • Author

    Chehab, M.I. ; Abdallah, A.E.

  • Author_Institution
    E-Security Res. Centre, London South Bank Univ., London, UK
  • fYear
    2009
  • fDate
    9-12 Nov. 2009
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Identity management (IDM) is a pillar upon which all security goals are usually founded. Recent years have witnessed the emergence of a large number of new technologies for IDM systems such as Kerberos, Microsoft Passport, Shibboleth and Liberty Alliance. On the one hand, these systems offer organizations and service providers features which widely open new opportunities for doing business and facilitating work internally within organizations. On the other, they present new threats because of the additional risks arising from implicit trust to third parties. Hence, all these gains may have to be carefully balanced with the non-transparent risks to information privacy and integrity arising from implicit chains of trusts inherent in IDM systems. This paper presents a sample of two abstract, concise and generic architectures upon which some of the emerging IDM systems are based. On one hand, these architectures allow us to understand the features provided in each system and, therefore, being able to compare, contrast and evaluate these systems. On the other hand, since the trust relationship in these architectures are make explicit, this work provides the foundation for future investigation and analysis of security risks emerging from the trust relationships inherent in each of these architectures.
  • Keywords
    biometrics (access control); security of data; Kerberos; Liberty Alliance; Microsoft Passport; Shibboleth; identity management; information integrity; information privacy; security risks; trusts; Collaboration; Disaster management; Electronic learning; Electronic mail; Identity management systems; Privacy; Public key; Security; Social network services; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Internet Technology and Secured Transactions, 2009. ICITST 2009. International Conference for
  • Conference_Location
    London
  • Print_ISBN
    978-1-4244-5647-5
  • Type

    conf

  • DOI
    10.1109/ICITST.2009.5402603
  • Filename
    5402603