A user-centric federated single sign-on system

被引:29
作者
Suriadi, Suriadi [1 ]
Foo, Ernest [1 ]
Josang, Audun [1 ]
机构
[1] Queensland Univ Technol, Informat Secur Inst, Brisbane, Qld 4001, Australia
关键词
Identity management; Privacy; Private credential; Single sign-on; User-centric;
D O I
10.1016/j.jnca.2008.02.016
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Current identity management systems are not concerned with user privacy. Users must assume that identity providers and service providers will ensure their privacy, which is not always the case. This paper proposes an extension of the existing federated single sign-on (FSSO) systems that adopts the beneficial properties of the user-centric identity management (UCIM) model. This new identity management system allows the users to control and enforce their privacy requirements while still retaining the convenience of single sign-on over a federation of service providers. Colored Petri Nets are used to formally model the new identity management system to provide assurance that the privacy goals are achieved. To our knowledge, Colored Petri Nets have not been used to model privacy in identity management systems before. (C) 2008 Elsevier Ltd. All rights reserved.
引用
收藏
页码:388 / 401
页数:14
相关论文
共 25 条
  • [1] ALLIANCE L, 2004, LIBERTY ID FF ARCHIT
  • [2] ALY S, 2004, TR04003 CTI DEP U SC
  • [3] [Anonymous], 2006, Identity Crisis: How Identification Is Overused and Misunderstood
  • [4] BANGERTER E, 2004, LECT NOTES COMPUTER, V3957, P43
  • [5] Bhargav-Spantzel A., 2006, LTRC-TR31, P1, DOI DOI 10.1145/1179529.1179531
  • [6] A coloured Petri net approach to protocol verification
    Billington, J
    Gallasch, GE
    Han, B
    [J]. LECTURES ON CONCURRENCY AND PETRI NETS: ADVANCES IN PETRI NETS, 2004, 3098 : 210 - 290
  • [7] Camenisch J, 2004, LECT NOTES COMPUT SC, V3152, P56
  • [8] Camenisch J, 2003, LECT NOTES COMPUT SC, V2576, P268
  • [9] Camenisch J, 2003, LECT NOTES COMPUT SC, V2729, P126
  • [10] CAMENISCH J, 2005, DIM 2005, P20