首页> 外文会议>International Conference on Information Science and Applications >Scalable, Privacy-preserving Remote Attestation in and through Federated Identity Management Frameworks
【24h】

Scalable, Privacy-preserving Remote Attestation in and through Federated Identity Management Frameworks

机译:通过联邦身份管理框架和通过联邦身份管理框架可扩展,隐私保留远程证明

获取原文
获取外文期刊封面目录资料

摘要

Creating trustworthy online computing is an important open issue in security research. Trusted Computing aims to address this problem through the use of remote attestation but comes with its own baggage in the form of privacy concerns. Federated Identity Management Systems (FIDMSs), on the other hand, provide another form of trust but lack the ability to measure the integrity of platforms that they vouch for. We note that these two security architectures have reciprocal strengths and weaknesses and can be combined to create an architecture that addresses the concerns of both. In this paper, we propose an extended FIDMS in which the identity provider not only vouches for the identity of a user but also for her platform's integrity. In this way, we (a) allow a service provider to establish trust on a client platform's integrity without sacrificing privacy; and (b) create a feasible and scalable architecture for remote attestation. We describe our proposed architecture in the context of Shibboleth FIDMS and provide the details of the implementation of this system.
机译:创建值得信赖的在线计算是安全研究中的一个重要开放问题。值得信赖的计算旨在通过使用远程证明来解决这个问题,而是以其隐私问题的形式随身携带自己的行李。另一方面,联邦身份管理系统(FIDMS)提供了另一种形式的信任,但缺乏能够衡量他们保证的平台的完整性。我们注意到,这两个安全架构具有互惠优势和缺点,可以组合以创建解决两者患者的架构。在本文中,我们提出了一个扩展的FIDM,其中身份提供者不仅为了用户的身份而且为她的平台的完整性而挥之不去。通过这种方式,我们(a)允许服务提供商在不牺牲隐私的情况下对客户平台的完整性建立信任; (b)创建可行和可扩展的架构,可用于远程证明。我们在Shibboleth FIDMS的背景下描述了我们提出的架构,并提供了该系统实现的细节。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号