...
首页> 外文期刊>International Journal of Computer Systems Science & Engineering >Towards a person-centric identity management infrastructure (IMI)
【24h】

Towards a person-centric identity management infrastructure (IMI)

机译:迈向以人为本的身份管理基础架构(IMI)

获取原文
获取原文并翻译 | 示例
           

摘要

When people sign in to Information Systems today, they usually present credentials with local significance, to be authenticated and gain access to internal functionality. Every user is therefore required to have a different login-password combination for each online service, or even different credentials for different roles within a service. As a result users tend to make poor password choices that are easy to remember, or even repeat the same login-password information for different services. This poses security threats to service providers and a privacy risk for end-users. The solution is to shift to identity management systems. Such a system will issue a digital identity for every user and will be able to control the full life-cycle of these identities, from creation to termination. A significant advantage of such a system is the single sign-on mechanism, whereby a single action of user authentication and authorization can permit the user to access multiple services without the need to execute any local authentication procedure. We first evaluate existing identity management implementations and then proceed to propose our own solution. Our Identity Management Infrastructure (IMI) differs from similar approaches. We propose a global scale deployment and we address problems that arise from such a design. Another difference is that our technique sets up the end-user as the sole holder of his/her identity information. This prevents the existence of a single point where multiple digital identities are held, which could become a target for potential attackers. The benefits (as seen from our approach) are improved security, accountability, reduced administration costs, ease of deployment and privacy protection. We provide accountability to digital identity holders, while allowing the user to remain anonymous and give service providers and end-users strong security guarantees about the security aspects of our approach. We finally study the security risks involved in our approach and how we address them.
机译:人们今天登录信息系统时,通常会提供具有本地意义的凭证,以进行身份​​验证并获得对内部功能的访问权限。因此,每个用户都需要为每个在线服务具有不同的登录密码组合,或者甚至对于服务中的不同角色具有不同的凭据。结果,用户倾向于做出容易记住的错误密码选择,甚至针对不同的服务重复相同的登录密码信息。这对服务提供商构成了安全威胁,并给最终用户带来了隐私风险。解决方案是转向身份管理系统。这样的系统将为每个用户发布数字身份,并将能够控制这些身份的整个生命周期,从创建到终止。这种系统的显着优势是单点登录机制,通过这种方式,用户身份验证和授权的单一操作即可允许用户访问多个服务,而无需执行任何本地身份验证过程。我们首先评估现有的身份管理实现,然后继续提出我们自己的解决方案。我们的身份管理基础架构(IMI)与类似的方法不同。我们建议在全球范围内进行部署,并解决由这种设计引起的问题。另一个区别是我们的技术将最终用户设置为他/她的身份信息的唯一持有者。这可以防止存在多个数字身份的单一点,而这可能成为潜在攻击者的目标。收益(从我们的方法中可以看出)是改进的安全性,问责制,降低的管理成本,易于部署和隐私保护。我们向数字身份持有者提供责任,同时允许用户保持匿名,并就我们的方法的安全性方面为服务提供商和最终用户提供强有力的安全保证。我们最终研究了我们的方法所涉及的安全风险以及如何解决这些风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号