【24h】

IDENTIA? - AN IDENTITY BRIDGE INTEGRATING OPENID AND SAML FOR ENHANCED IDENTITY TRUST AND USER ACCESS CONTROL

机译:IDENTIA? -集成OPENID和SAML的身份桥,用于增强身份信任和用户访问控制

获取原文
获取原文并翻译 | 示例

摘要

Many companies and government agencies are facingrnconstant challenges of protecting vast information assetsrnfrom malicious access while providing end users withrnconvenient mechanism to share information. The keyrnenabler in meeting these challenges is to establish a robustrnand scalable Identity and Access Management (IdAM)rnsystem based on open standards. While OpenID-basedrnstandards have been embraced by many online servicernproviders, many believe that these implementations lackrnthe necessary confidence level in user identity trust andrninteroperability. On the other hands, SAML has been thernde-facto IdAM solution in the enterprise world due to itsrnrobustness and trust framework. However, for the mostrnpart, SAML lacks the flexibility and convenience inrnsupporting RESTful applications.rnAs the result of a SBIR research project funded byrnthe Air Force, IDentia is an open-source based productrnthat provides an online IdAM solution. It implements anrnidentity bridge that integrates the flexibility of OpenIDrnwith the robustness of SAML, enabling PKI basedrnauthentication and ABAC-driven authorization in thernenterprise environment. This paper introduces thernfundamentals and standards of the IdAM technology,rnidentifies the security limitations in the currentrnimplementations, and describes architecture design andrnimplementation of IDentia as a solution for enterprisernIdAM.
机译:许多公司和政府机构在保护庞大的信息资产不受恶意访问的同时为最终用户提供便捷的信息共享机制方面面临着不断的挑战。应对这些挑战的关键是建立基于开放标准的健壮且可扩展的身份和访问管理(IdAM)系统。尽管许多在线服务提供商已经采用了基于OpenID的标准,但许多人认为这些实现缺乏对用户身份信任和互操作性的必要置信度。另一方面,由于SAML的健壮性和信任框架,它已成为企业界最常见的IdAM解决方案。但是,在大多数情况下,SAML缺乏支持RESTful应用程序的灵活性和便利性。作为空军资助的SBIR研究项目的结果,IDentia是提供在线IdAM解决方案的基于开源的产品。它实现了身份桥,将OpenIDrn的灵活性与SAML的强大功能集成在一起,从而在企业环境中实现了基于PKI的身份验证和ABAC驱动的授权。本文介绍了IdAM技术的基本原理和标准,确定了当前实现中的安全限制,并介绍了IDentia的体系结构设计和实现作为企业IDAM的解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号