首页> 外文会议>International Conference on E-Commerce and Web Technologies(EC-Web 2006) >Attribute-Based Authentication and Authorisation Infrastructures for E-Commerce Providers
【24h】

Attribute-Based Authentication and Authorisation Infrastructures for E-Commerce Providers

机译:基于属性的电子商务提供商的身份验证和授权基础架构

获取原文

摘要

Authentication and authorisation has been a basic and necessary service for internet transactions. With the evolution of e-commerce, traditional mechanisms for data security and access control are becoming outdated. Several new standards have emerged which allow dynamic access control based on exchanging user attributes. Unfortunately, while providing highly secure and flexible access mechanisms is a very demanding task, it cannot be considered a core competency for most e-commerce corporations. Therefore, a need to outsource or at least share such services with other entities arises. Authentication and Authorisation Infrastructures (AAIs) can provide such integrated federations of security services. They could, in particular, provide attribute-based access control (ABAC) mechanisms and mediate customers' demand for privacy and vendors' needs for information. We propose an AAI reference model that includes ABAC functionality based on the XACML standard and lessons learned from various existing AAIs. AAIs analysed are AKENTI, CARDEA, CAS, GridShib, Liberty ID-FF, Microsoft .NET Passport, PAPI, PERMIS, Shibboleth and VOMS.
机译:身份验证和授权是互联网交易的基本和必要服务。随着电子商务的演变,数据安全和访问控制的传统机制已经过时。已经出现了几种新标准,其允许基于交换用户属性的动态访问控制。不幸的是,在提供高度安全和灵活的访问机制的同时是一个非常苛刻的任务,它不能被认为是大多数电子商务公司的核心竞争力。因此,需要使用外包或至少与其他实体分享此类服务。身份验证和授权基础架构(AAIS)可以提供如此集成的安全服务联合。特别是他们可以提供基于属性的访问控制(ABAC)机制,并调解客户对隐私的需求和供应商的信息需求。我们提出了一个AAI参考模型,包括基于XACML标准的ABAC功能和来自各种现有AAIS的经验教训。 AAIS分析是Akenti,Cardea,CAS,Gridshib,Liberty ID-FF,Microsoft .Net Passport,Papi,Permis,Shibboleth和Voms。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号