首页> 外文会议>IFIP/IEEE International Symposium on Integrated Network Management >Towards usable and reasonable Identity Management in heterogeneous IT infrastructures
【24h】

Towards usable and reasonable Identity Management in heterogeneous IT infrastructures

机译:在异构IT基础设施中实现可用合理的身份管理

获取原文

摘要

Identity Management (IDM) has driven many IT projects especially in large IT infrastructures. Like other projects that focused on security or authentication, e.g. Public Key Infrastructures (PKI), they do not only reduce complexity and ease administration, but have to be managed themselves. This leads to costs and effort being necessary before gaining the benefit of unified authentication. This is maybe a reason why many projects dealing with IDM failed in the past or didn't reach their initial goals. Nevertheless the trend to use decentralized access to resources e.g. via the Internet or World Wide Web seems unbroken - demanding for solutions to decentrally authenticate users. New techniques like Identity Federations address this requirement and extend Identity Management geographically. This paper shows ways to measure Identity Management efficiency and to enable balance between usability which influences the effort needed to authenticate and the resulting established security levels. This balance is defined as the key to reasonable and efficient Identity Management solutions in the future. Experience is gained from an Identity Management project to unify authentication in heterogeneous scientific IT infrastructures. The presented model and the lessons learned can be adopted for forthcoming Identity Management projects in other organizations or support decisions about future IDM projects. Beyond unveiling drawbacks of classical IDM solutions and showing solutions, the paper gives a concluding outlook on future IDM developments and upcoming challenges for authentication and security or access management.
机译:身份管理(IDM)推动了许多IT项目,特别是在大型IT基础架构中。与专注于安全或认证的其他项目一样,例如,公共关键基础设施(PKI),它们不仅可以减少复杂性和缓解管理,但必须自己管理。在获得统一认证的利益之前,这导致成本和努力。这可能是为什么处理IDM的许多项目过去失败的原因或没有达到最初的目标。然而,使用分散访问资源的趋势例如。通过互联网或全球网络似乎是不间断的 - 对特定认证用户的解决方案苛刻。新技术,如身份联盟,地理位置地解决了这一要求并扩展了身份管理。本文显示了衡量身份管理效率的方法,并在可用性之间实现平衡,这影响了验证所需的努力和所产生的安全级别。该余额被定义为未来合理和高效的身份管理解决方案的关键。从身份管理项目中获得了经验,以统一异构科学IT基础架构的认证。所提出的模型和所学的经验教训可以在其他组织中即将到来的身份管理项目或关于未来IDM项目的决定。除了普遍揭示古典IDM解决方案的缺点并显示解决方案,本文给出了未来IDM开发的结论前景,即将到来的身份验证和安全或访问管理的挑战。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号