首页> 外文会议> >Towards usable and reasonable Identity Management in heterogeneous IT infrastructures
【24h】

Towards usable and reasonable Identity Management in heterogeneous IT infrastructures

机译:在异构IT基础架构中实现可用和合理的身份管理

获取原文

摘要

Identity Management (IDM) has driven many IT projects especially in large IT infrastructures. Like other projects that focused on security or authentication, e.g. Public Key Infrastructures (PKI), they do not only reduce complexity and ease administration, but have to be managed themselves. This leads to costs and effort being necessary before gaining the benefit of unified authentication. This is maybe a reason why many projects dealing with IDM failed in the past or didn''t reach their initial goals. Nevertheless the trend to use decentralized access to resources e.g. via the Internet or World Wide Web seems unbroken - demanding for solutions to decentrally authenticate users. New techniques like Identity Federations address this requirement and extend Identity Management geographically. This paper shows ways to measure Identity Management efficiency and to enable balance between usability which influences the effort needed to authenticate and the resulting established security levels. This balance is defined as the key to reasonable and efficient Identity Management solutions in the future. Experience is gained from an Identity Management project to unify authentication in heterogeneous scientific IT infrastructures. The presented model and the lessons learned can be adopted for forthcoming Identity Management projects in other organizations or support decisions about future IDM projects. Beyond unveiling drawbacks of classical IDM solutions and showing solutions, the paper gives a concluding outlook on future IDM developments and upcoming challenges for authentication and security or access management.
机译:身份管理(IDM)推动了许多IT项目,特别是在大型IT基础架构中。与其他专注于安全性或身份验证的项目一样,例如公钥基础结构(PKI),它们不仅降低了复杂性并简化了管理,而且必须自己进行管理。这导致在获得统一身份验证的好处之前必须付出成本和精力。这也许就是为什么许多与IDM有关的项目过去失败或没有达到其最初目标的原因。尽管如此,使用分散访问资源的趋势仍然存在,例如:通过Internet或World Wide Web似乎不间断-要求用于分散验证用户身份的解决方案。诸如身份联合会之类的新技术可解决此要求,并在地理上扩展身份管理。本文展示了一些方法,这些方法可用来衡量身份管理效率并实现可用性之间的平衡,该可用性会影响身份验证所需的工作量以及由此产生的既定安全级别。这种平衡被定义为将来获得合理,有效的身份管理解决方案的关键。从身份管理项目中获得经验,以统一异构科学IT基础架构中的身份验证。所提供的模型和所汲取的教训可用于其他组织即将推出的身份管理项目,或支持有关未来IDM项目的决策。除了揭示经典IDM解决方案的缺点并展示解决方案之外,本文还对IDM的未来发展以及身份验证和安全性或访问管理的挑战提出了最终的展望。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号