【24h】

Privacy Preserved Attribute Aggregation to Avoid Correlation of User Activities across Shibboleth SPs

机译:保留隐私的属性聚合可避免Shibboleth SP之间用户活动的相关性

获取原文

摘要

Privacy is one of the most important issues in Identity Federation, a technology in which local IDs and credentials such as passwords managed at one site may be used to access many online services, including cloud services provided outside of users' organization. Attribute aggregation is an advanced technique that may be employed in identity federation, collecting attributes about a user from multiple distinct identities to provide a complete picture about a user necessary for some services. However, conventional methods of attribute aggregation require a persistent shared unique ID. This may restrict the use of federated identity for some services because these unique ID's could be used by bad actors to correlate user activity or user data. This paper proposes a new method of attribute aggregation that doesn't require a universal unique ID. SAML, a widely used federated identity standard, is used as the basis for this work. This privacy-preserving attribute aggregation technique has been validated with a successful implementation for the open source federated identity software project Shibboleth.
机译:隐私是Identity Federation中最重要的问题之一,在该技术中,可以使用本地ID和凭据(例如在一个站点管理的密码)来访问许多在线服务,包括在用户组织外部提供的云服务。属性聚合是可以在身份联合中使用的高级技术,可以从多个不同的身份收集有关用户的属性,以提供有关某些服务所需的用户的完整图片。但是,传统的属性聚合方法需要持久的共享唯一ID。这可能会限制对某些服务使用联合身份,因为不良行为者可能会使用这些唯一的ID来关联用户活动或用户数据。本文提出了一种不需要通用唯一ID的属性聚合新方法。 SAML是一种广泛使用的联盟身份标准,被用作这项工作的基础。这种保护隐私的属性聚合技术已通过开源联合身份软件项目Shibboleth的成功实施得到验证。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号