Can we create a cross-domain federated identity for the industrial internet of things without google?

被引:4
作者
Kim, Eunsoo [1 ]
Cho, Young-Seob [2 ]
Kim, Bedeuro [3 ]
Ji, Woojoong [4 ]
Kim, Seok-Hyun [2 ]
Woo, Simon S. [5 ]
Kim, Hyoungshick [1 ]
机构
[1] Department of Computer Science and Engineering, Sungkyunkwan University
[2] Department of Computer Science and Engineering, Sungkyunkwan University
[3] Department of Information Security, Joongbu University
[4] University of Southern California, Los Angeles
来源
IEEE Internet of Things Magazine | 2020年 / 3卷 / 04期
关键词
Authentication - Authorization - Digital devices - Information management;
D O I
10.1109/IOTM.0001.2000050
中图分类号
学科分类号
摘要
Providing a cross-domain federated identity is essential for next-generation Internet services because information about user identity should be seamlessly exchanged across different domains for authentication and authorization. Federated identity can enable users to use various services through a single account. However, conventional federated identity management systems necessarily require a trustworthy identity provider who stores user identity information and presents it to other service providers. Unfortunately, this requirement may not be acceptable in Industrial Internet of Things (IIoT) applications, which often require interacting and authenticating with users and devices across different domains. Who will take full responsibility for managing and issuing all digital identities for IIoT devices? Can we really trust one superpower organization to manage all the identities and credentials of IIoT devices? In this article, we provide an overview of centralized and decentralized identity management methods and examine the feasibility of those methods for IIoT applications. To overcome the inherent limitations of existing approaches, we are specifically interested in designing decentralized cross-domain federated identity management using blockchain. Our Copernican idea brings new and important perspectives in establishing universal cosmopolitan cross-domain federated identity management in a secure and fair manner. © 2018 IEEE.
引用
收藏
页码:82 / 87
页数:5
相关论文
共 18 条
[1]  
Maler E., Reed D., The venn of identity: Options and issues in federated identity management, IEEE Security & Privacy, 6, 2, pp. 16-23, (2008)
[2]  
Shim S.S., Bhalla G., Pendyala V., Federated identity management, Computer, 38, 12, pp. 120-122, (2005)
[3]  
De Clercq J., Single sign-on architectures, Proc. Int'L. Conf. Infrastructure Security, pp. 40-58, (2002)
[4]  
Berghel H., Equifax and the latest round of identity theft roulette, Computer, 50, 12, pp. 72-76, (2017)
[5]  
Isaac M., Frenkel S., Facebook Security Breach Exposes Accounts of 50 Million Users, (2018)
[6]  
Tobin A., Reed D., The Inevitable Rise of Self-Sovereign Identity, (2016)
[7]  
Lundkvist C., Et al., UPort: A Platform for Self-Sovereign Identity, (2016)
[8]  
Kilroe J., Civic: Token Behavior Model, (2018)
[9]  
Hardt D., The OAuth 2.0 Authorization Framework, (2012)
[10]  
Sakimura N., Et al., OpenID Connect Core 1.0, (2014)