首页> 外文会议>International conference on availability, reliability and security >Increasing the Resilience and Trustworthiness of OpenID Identity Providers for Future Networks and Services
【24h】

Increasing the Resilience and Trustworthiness of OpenID Identity Providers for Future Networks and Services

机译:提高OpenID身份提供商对未来网络和服务的弹性和可信赖性

获取原文

摘要

We introduce a set of tools and techniques for increasing the resilience and trustworthiness of identity providers (IdPs) based on OpenID. To this purpose we propose an architecture of specialized components capable of fulfilling the essential requirements for ensuring high availability, integrity and higher confidentiality guarantees for sensitive data and operations. Additionally, we also discuss how trusted components (e.g., TPMs, smart cards) can be used to provide remote attestation on the client and server side, i.e., how to measure the trustworthiness of the system. The proposed solution outperforms related work in different aspects, such as countermeasures for solving different security issues, throughput, and by tolerating arbitrary faults without compromising the system operations. We evaluate the system behavior under different circumstances, such as continuous faults and attacks. Furthermore, the first performance evaluations show that the system is capable of supporting environments with thousands of users.
机译:我们介绍了一套工具和技术,用于提高基于OpenID的身份提供者(IdP)的弹性和可信赖性。为此,我们提出了一种专用组件的体系结构,该组件能够满足基本要求,以确保对敏感数据和操作的高可用性,完整性和更高的机密性保证。此外,我们还讨论了如何使用可信组件(例如TPM,智能卡)在客户端和服务器端提供远程证明,即如何衡量系统的可信度。所提出的解决方案在各个方面都胜过相关工作,例如用于解决不同安全性问题的对策,吞吐量以及通过容忍任意故障而不会损害系统运行。我们评估系统在不同情况下的行为,例如连续故障和攻击。此外,首次性能评估表明该系统能够支持成千上万用户的环境。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号