首页> 外文会议>8th symposium on identity and trust on the internet 2009 >FileSpace An Alternative to CardSpace that supports Multiple Token Authorisation and Portability Between Devices
【24h】

FileSpace An Alternative to CardSpace that supports Multiple Token Authorisation and Portability Between Devices

机译:FileSpace CardSpace的替代方案,支持多个令牌授权和设备之间的可移植性

获取原文
获取外文期刊封面目录资料

摘要

This paper describes a federated identity management system based on long lived encrypted credential files rather than virtual cards and short lived assertions. Users obtain their authorisation credential files from their identity providers and have them bound to their public key certificates, which can hold any pseudonym the user wishes. Users can then use these credentials multiple times without the identity providers being able to track their movements and without having to authenticate to the IdP each time. The credentials are worthless to an attacker if lost or stolen, therefore they do not need any special protection mechanisms. They can be copied freely between multiple devices, and users can use multiple credentials in a single transaction. Users only need to authenticate to their private key store in order for it to produce a signed token necessary for the service provider to authenticate the user and decrypt the authorisation credentials. The signed token is bound to the service provider and is short lived to prevent man in the middle attacks.
机译:本文介绍了一种基于长期加密凭证文件而非虚拟卡和短期断言的联合身份管理系统。用户从其身份提供者那里获取他们的授权证书文件,并将它们绑定到其公共密钥证书上,该证书可以包含用户希望的任何假名。然后,用户可以多次使用这些凭据,而身份提供者无需跟踪其活动,而不必每次都向IdP进行身份验证。如果凭据丢失或被盗,它们对于攻击者将毫无价值,因此它们不需要任何特殊的保护机制。可以在多个设备之间自由复制它们,并且用户可以在单个事务中使用多个凭证。用户只需要向其私钥存储进行身份验证即可使其生成服务提供商对用户进行身份验证和解密授权凭证所必需的签名令牌。签名的令牌绑定到服务提供商,并且存在短暂的时间,以防止中间人受到攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号