【24h】

A Flexible and Compatible Model for Supporting Assurance Level through a Central Proxy

机译:灵活且兼容的模型,用于通过中央代理服务器支持保证水平

获取原文

摘要

Generally, methods of authentication and identification utilized in asserting users' credentials directly affect security of offered services. In a federated environment, service owners must trust external credentials and make access control decisions based on Assurance Information received from remote Identity Providers (IdPs). Communities (e.g. NIST, IETF and etc.) have tried to provide a coherent and justifiable architecture in order to evaluate Assurance Information and define Assurance Levels (AL). Expensive deployment, limited service owners' authority to define their own requirements and lack of compatibility between heterogeneous existing standards can be considered as some of the unsolved concerns that hinder developers to openly accept published works. By assessing the advantages and disadvantages of well-known models, a comprehensive, flexible and compatible solution is proposed to value and deploy assurance levels through a central entity called Proxy.
机译:通常,在声明用户凭据时使用的身份验证和标识方法直接影响所提供服务的安全性。在联合环境中,服务所有者必须信任外部凭据,并根据从远程身份提供商(IdP)收到的保证信息做出访问控制决策。社区(例如NIST,IETF等)试图提供一种连贯且合理的架构,以评估保证信息并定义保证级别(AL)。昂贵的部署,有限的服务拥有者定义自己的要求的权限以及异构现有标准之间缺乏兼容性,可以看作是一些尚未解决的问题,这些问题阻碍了开发人员公开接受已发表的作品。通过评估众所周知的模型的优缺点,提出了一种全面,灵活和兼容的解决方案,以通过称为代理的中央实体来评估和部署保证级别。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号