首页> 外文会议>IEEE/IFIP Network Operations and Management Symposium >Reliability and Scalability Improvements to Identity Federations by managing SAML Metadata with Distributed Ledger Technology
【24h】

Reliability and Scalability Improvements to Identity Federations by managing SAML Metadata with Distributed Ledger Technology

机译:通过管理分布式分区技术的SAML元数据对身份联合的可靠性和可扩展性改进

获取原文

摘要

In identity federations, users assigned to identity providers (IDPs) can access applications operated by service providers (SPs) without SP-specific credentials for authentication and authorization. While OpenID Connect and SAML are the two most widely adopted federation standards, using them inherently results in a trade-off between data quality guarantees and scalability, given how they handle the Metadata about the involved IDPs and SPs. This paper presents a novel approach for federation membership and federation Metadata management based on Distributed Ledger Technology. It applies the core idea of Certificate Transparency, as known from Global-PKI certificate authorities for X.509v3 server certificates, to SAML federation Metadata; therefore, it achieves OpenID Connect's federation building flexibility without losing the significant advantages of traditional SAML federations. An implementation based on Hyperledger Fabric is used to evaluate typical use cases by measuring impacts on Metadata distribution latency and Metadata size, and to discuss the feasibility of the presented approach.
机译:在身份联盟中,分配给身份提供者(IDP)的用户可以访问由服务提供商(SPS)操作的应用程序,而没有SP特定的凭据进行身份验证和授权。虽然OpenID Connect和Saml是两个最广泛采用的联盟标准,但在数据质量保证和可扩展性之间,使用它们在权衡中,鉴于它们如何处理涉及的IDP和SPS的元数据。本文提出了一种基于分布式分区技术的联邦成员资格和联邦元数据管理的新方法。它适用于证书透明度的核心概念,从全球PKI证书机构为X.509v3服务器证书中已知的,到SAML联合元数据;因此,它实现了OpenID连接的联邦建设灵活性,而不会失去传统SAML联合的显着优势。基于超载体结构的实现用于通过测量对元数据分发延迟和元数据大小的影响来评估典型用例,并讨论所提出的方法的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号