首页> 外文会议>The 11th IEEE/IPSJ International Symposium on Applications and the Internet >Federated Authentication in a Hierarchy of IdPs by Using Shibboleth
【24h】

Federated Authentication in a Hierarchy of IdPs by Using Shibboleth

机译:使用Shibboleth在IdP层次结构中进行联合身份验证

获取原文

摘要

By using widespread single sign-on (SSO) technologies, it is becoming common that services are provided in the form of SSO. However, it is also becoming common that the structure of IdPs is complex. A single person may have his/her identity in an organizations, in its sub organizations, and possibly in a virtual organization. A problem is that such identities are provided by independent IdPs. Considering that a major motivation of SSO is that we can reduce cost by integrating authentication, this scenario is never desirable. To solve this problem, we propose a hierarchy of IdPs. In particular, an IdP in a sub organization can rely on assertions of its parent organization, which enables authentication delegation. Moreover, delegation of authentication introduces hierarchy of trust. We define its protocol based on the idea that an IdP also issues authentication request to other IdPs as usual SPs. Its prototype implementation on Shibboleth is also shown. Our authentication delegation is widely applicable to actual scenarios in hierarchically organized institutions and virtual organizations.
机译:通过使用广泛的单点登录(SSO)技术,以SSO形式提供服务已变得越来越普遍。但是,IdP的结构复杂也变得很普遍。一个人可能在组织,其子组织以及可能在虚拟组织中具有其身份。问题是这样的身份是由独立的IdP提供的。考虑到SSO的主要动机是我们可以通过集成身份验证来降低成本,因此这种情况永远都是不可取的。为了解决这个问题,我们提出了一个IdP的层次结构。特别是,子组织中的IdP可以依靠其父组织的声明,从而启用身份验证委派。此外,身份验证的委派引入了信任的层次结构。我们基于IdP还向其他IdP发出身份验证请求的想法来定义其协议,这些身份验证请求与通常的SP一样。还显示了其在Shibboleth上的原型实现。我们的身份验证委派可广泛应用于分层组织机构和虚拟组织中的实际方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号