【24h】

Portable Personal Identity Provider in Mobile Phones

机译:手机中的便携式个人身份提供商

获取原文
获取原文并翻译 | 示例

摘要

This paper analyses the prospect of having a Portable Personal Identity Provider (PPIdP, in short) in the mobile phone. The ubiquitous presence of powerful mobile phones equipped with high speed networks can be utilised to make the mobile phone act as a portable and personal Identity Provider (IdP, in short) on behalf of their users. Such an IdP would be helpful for the user in the sense that it will provide a central location to manage different user attributes which are generally scattered among different service providers in the traditional setting of online services. In addition, the user needs to trust the provider to store those attributes securely which may not be always honoured and crucial user attributes may be abused. Creating a Personal Identity Federation using a personal IdP can tackle many of these stated problems. Moreover, such an IdP may provide additional advantages. We have developed such a Mobile IdP for the Android platform based on the Security Assertion Markup Language (SAML) and OpenID as a proof of concept using the Jetty Web Server. In this paper, we discuss the functionalities of our developed IdP and the technical challenges we have faced. Moreover, we analyse the security, privacy and trust issues involved in having such an IdP and the advantages it offers.
机译:本文分析了在手机中配备便携式个人身份提供商(PPIdP)的前景。配备有高速网络的功能强大的移动电话无处不在,可以使移动电话代表其用户充当便携式和个人身份提供者(简称IDP)。从某种意义上说,这种IdP将为用户提供帮助,因为它将提供一个中心位置来管理通常在传统的在线服务环境中分散在不同服务提供商之间的不同用户属性。另外,用户需要信任提供者来安全地存储可能不总是兑现的那些属性,并且可能滥用关键的用户属性。使用个人IdP创建个人身份联盟可以解决许多上述问题。而且,这种IdP可以提供其他优势。我们已经使用Jetty Web服务器基于安全断言标记语言(SAML)和OpenID为Android平台开发了这样的移动IdP,作为概念证明。在本文中,我们讨论了我们开发的IdP的功能以及我们面临的技术挑战。此外,我们分析了拥有此类IdP所涉及的安全性,隐私和信任问题及其优势。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号