首页> 外文会议>IFIP-TC 6/TC 11 international conference on communications and multimedia security >A Federated Cloud Identity Broker-Model for Enhanced Privacy via Proxy Re-Encryption
【24h】

A Federated Cloud Identity Broker-Model for Enhanced Privacy via Proxy Re-Encryption

机译:通过代理重新加密增强隐私的联邦云身份经纪模型

获取原文

摘要

Reliable and secure user identification and authentication are key enablers for regulating access to protected online services. Since cloud computing gains more and more importance, identification and authentication in and across clouds play an increasing role in this domain too. Currently, existing web identity management models are often just mapped to the cloud domain. Besides, within recent years several cloud identity management models such as the cloud identity broker-model have emerged. In the aforementioned model, an identity broker in the cloud acts as hub between various service and identity providers. While this seems to be a promising approach for adopting identity management in cloud computing, still some problems can be identified. A notable issue is the dependency of users and service providers on the same central broker for identification and authentication processes. Additionally, letting an identity broker store or process sensitive data such as identity information in the cloud brings up new issues, in particular with respect to user's privacy. To overcome these problems, we propose a new cloud identity management model based on the federation between different cloud identity brokers. Thereby, users and service providers can select their favorite cloud identity broker without being dependent on one and the same broker. Moreover, it enhances user's privacy by the use of appropriate cryptographic mechanisms and in particular proxy re-encryption. Besides introducing the model we also provide a proof of concept implementation thereof.
机译:可靠和安全的用户标识和身份验证是用于调节对受保护在线服务的访问的关键支持者。由于云计算增加了越来越重要的,但云中的识别和身份验证也在该域中发挥着越来越大的作用。目前,现有的Web身份管理模型通常只是映射到云域。此外,近年来,几个云身份管理模型,如云身份经纪模型出现。在上述模型中,云中的身份代理作为各种服务和身份提供者之间的集线器。虽然这似乎是采用云计算中的身份管理的有希望的方法,但仍然可以识别一些问题。值得注意的问题是用户和服务提供商在同一中心代理上的依赖性,以用于识别和认证过程。此外,允许云中的身份信息等工艺敏感数据,尤其是关于用户的隐私来提出新问题。为了克服这些问题,我们提出了一种基于不同云标识经纪之间联合的新云身份管理模型。因此,用户和服务提供商可以在不依赖于一个和同一代理的情况下选择他们喜欢的云标识代理。此外,它通过使用适当的加密机制和特定代理重新加密来增强用户的隐私。除了介绍模型外,我们还提供了其概念实现的证据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号