首页> 外文会议>2011 International Joint Conference of IEEE TrustCom-11/IEEE ICESS-11/FCST-11 >Design and Evaluation of an Architecture for Ubiquitous User Authentication Based on Identity Management Systems
【24h】

Design and Evaluation of an Architecture for Ubiquitous User Authentication Based on Identity Management Systems

机译:基于身份管理系统的无处不在用户认证体系结构的设计与评估

获取原文

摘要

Nowadays, users consume digital services with their digital identities on a multitude of different devices, e.g. notebooks, smart phones or even TV sets. Hereby, users are faced with additional challenges, i.e., devices have different security levels and not all digital identities must be used on all devices. Identities used for home banking should not be used on an insecure device and business identities should only be used on business devices. Moreover, it should be possible to switch between devices in a seamless way without the need to reauthenticate again on each device. Therefore, we propose an architecture that integrates all user devices and exploits identity management systems for ubiquitous user authentication. The proposed architecture improves usability by reducing the number of manual authentication procedures, by relaying authentication to devices with appropriate input capabilities and by supporting the user in identity selection. Security is improved by the possibility to perform authentication on secure devices, the provisioning of short-lived tokens to insecure devices and the opportunity to perform multifactor-authentication across devices. Our implementation is based on the Shibboleth IdM system and serves as proof-of-concept of our architecture. The conducted security evaluation confirms that our concept does not introduce additional security threats.
机译:如今,用户在许多不同的设备(例如移动设备)上使用具有数字身份的数字服务。笔记本电脑,智能手机甚至电视机。因此,用户面临额外的挑战,即,设备具有不同的安全级别,并且并非所有数字身份都必须在所有设备上使用。用于家庭银行业务的身份不应在不安全的设备上使用,而业务身份仅应在业务设备上使用。此外,应该有可能以无缝方式在设备之间切换,而无需在每个设备上再次进行重新认证。因此,我们提出了一种架构,该架构可集成所有用户设备并利用身份管理系统进行无处不在的用户身份验证。所提出的体系结构通过减少手动身份验证过程的数量,将身份验证中继到具有适当输入功能的设备以及通过支持用户的身份选择来提高可用性。通过在安全设备上执行身份验证,为不安全的设备提供短期令牌以及在设备之间执行多因素身份验证的机会,可以提高安全性。我们的实现基于Shibboleth IdM系统,并作为我们体系结构的概念验证。进行的安全评估确认,我们的概念不会引入其他安全威胁。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号