首页> 外文期刊>Future generation computer systems >Providing efficient SSO to cloud service access in AAA-based identity federations
【24h】

Providing efficient SSO to cloud service access in AAA-based identity federations

机译:在基于AAA的身份联盟中为云服务访问提供有效的SSO

获取原文
获取原文并翻译 | 示例
           

摘要

The inclusion of cloud services within existing identity federations has gained interest in the last years, as a way to simplify the access to them, reducing the user management costs, and increasing the utilization of the cloud resources. Whereas several federation technologies have been developed along the years for the Web world (e.g. SAML, Oauth, OpenID), non-web application services have been largely forgotten. The ABFAB IETF WG was created to define an architecture and a set of technologies for providing identity federation to non-Web application services, such as the cloud. ABFAB provides a way to use the existing EAP/AAA infrastructure to perform federated access control to any kind of application service, thanks to the definition of a new GSS-API mechanism called GSS-EAP. However, the ABFAB architecture does not define an efficient way of providing SSO. This paper defines a way to include such an SSO support into ABFAB, by introducing the required extensions to make use of the EAP Re-authentication Protocol (ERP), the IETF standard for providing fast re-authentication in EAP. Moreover, to demonstrate the feasibility of the proposed extensions, we have implemented a proof-of-concept based on Moonshot, the open-source implementation of ABFAB, and OpenStack as an example of cloud service. Finally, using this prototype we have completed a performance analysis that compares our proposal with the standard ABFAB operation. This analysis confirms the substantial reduction in terms of computational time and network traffic that can be achieved using ERP for providing efficient SSO to cloud service access in ABFAB-based identity federations.
机译:在过去的几年中,将云服务包含在现有的身份联盟中已经引起了人们的兴趣,这是一种简化对它们的访问,降低用户管理成本以及提高云资源利用率的方法。多年来,网络世界已经开发了几种联合技术(例如SAML,Oauth,OpenID),但非Web应用程序服务却在很大程度上被遗忘了。创建ABFAB IETF WG是为了定义用于向非Web应用程序服务(例如云)提供身份联盟的体系结构和一组技术。由于定义了称为GSS-EAP的新GSS-API机制,ABFAB提供了一种使用现有EAP / AAA基础结构对任何类型的应用程序服务执行联合访问控制的方法。但是,ABFAB体系结构没有定义提供SSO的有效方法。本文通过引入所需的扩展来利用EAP重新认证协议(ERP)(一种用于在EAP中提供快速重新认证的IETF标准),定义了一种将此类SSO支持包含到ABFAB中的方法。此外,为了证明所提议的扩展的可行性,我们基于Moonshot,ABFAB的开源实现以及OpenStack作为云服务的示例,实现了概念验证。最后,使用该原型,我们完成了性能分析,将我们的建议与标准ABFAB操作进行了比较。这项分析证实,使用ERP可以在基于ABFAB的身份联盟中向云服务访问提供有效的SSO,从而可以大大减少计算时间和网络流量。

著录项

  • 来源
    《Future generation computer systems》 |2016年第5期|13-28|共16页
  • 作者单位

    Department of Information and Communications Engineering (DIIC), University of Murcia, 30100, Spain,Facultad de Informatica, Campus de Espinardo S/N, 30100, University of Murcia, Spain;

    Department of Information and Communications Engineering (DIIC), University of Murcia, 30100, Spain;

    Department of Information and Communications Engineering (DIIC), University of Murcia, 30100, Spain;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    ABFAB/Moonshot; SSO; ERP; Identity; Federation;

    机译:ABFAB /月球射击;SSO;ERP;身份联邦;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号