ACM Home Page
Please provide us with feedback. Feedback
A delegation framework for federated identity management
Full text PdfPdf (249 KB)
Source Workshop On Digital Identity Management archive
Proceedings of the 2005 workshop on Digital identity management table of contents
Fairfax, VA, USA
SESSION: DIM frameworks table of contents
Pages: 94 - 103  
Year of Publication: 2005
ISBN:1-59593-232-1
Authors
Hidehito Gomi  NEC Internet Systems Research Laboratories, Kanagawa, JAPAN
Makoto Hatakeyama  NEC Internet Systems Research Laboratories, Kanagawa, JAPAN
Shigeru Hosono  NEC Internet Systems Research Laboratories, Kanagawa, JAPAN
Satoru Fujita  NEC Internet Systems Research Laboratories, Kanagawa, JAPAN
Sponsors
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
ACM: Association for Computing Machinery
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 21,   Downloads (12 Months): 169,   Citation Count: 3
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1102486.1102502
What is a DOI?

ABSTRACT

Identity federation is a powerful scheme that links accounts of users maintained distinctly by different business partners. The concept of network identity is a driver for accelerating automation of Web Services on the Internet for users on their behalf while protecting privacy of their personally identifiable information. Although users of Web Services essentially delegate some or all privileges to an entity to perform actions, current identity based systems do not take into sufficient consideration delegation between entities hosting Web Services from a viewpoint of identity and privacy. This paper introduces a delegation model for federated identity management systems and proposes a delegation framework to provide solutions for access control in the context of delegation. The framework has a function of transferring user's privileges across the entities encoded in delegation assertion extending SAML (Security Assertion Markup Language). The framework enables users to manage their own privileges, and service providers to control access of entities based on delegated privileges by the users with assistance of a delegation authority that authorizes delegation of a delegating entity and an authentication authority that authenticates a user and manages user's name identifiers.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

1
 
2
M. Ahsant, J. Basney, and O. Mulmo." "Grid Delegation Protocol".In Proceedings of the Workshop on Grid Security Practice and Experience July 2004.
 
3
 
4
BEA, IBM, Microsoft, RSA Security, and VeriSign. "Web Services Federation Language (WS-Federation)". Version 1.0, July 2003.
 
5
6
 
7
 
8
IBM, Microsoft, Actional, BEA, Computer Associates, Layer 7, Oblix, OpenNetwork, Ping Identity, Reactivity, and Verisign. "Web Services Trust Language (WS-Trust)", February 2005.
9
 
10
G. Navarro, B. Fironzabadi, E. Rissanen, and J. Borrell. "Constrained Delegation in XML-based Access Control and Digital Rights Management Standards". In Proceedings of Communication, Network, and Information Security (CNIS '03)2003.
 
11
OASIS. "Web Services Security: SOAP Message Security 1.0". OASIS Standard, March 2004.
 
12
OASIS. "Assertions and Protocol for the OASIS Security Assertion Markup Language (SAML)V2.0". OASIS Standard, March 2005.
 
13
OECD. "OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data", 2004.http://www.oecd.org/document/18/0,2340, en_2649 201185_1815186_1_1_1_1,00.html
 
14
OPA. "Guidelines for Online Privacy Policies". http://www.privacyalliance.org/resources/ppguidelines.shtml
 
15
Liberty Alliance Project. "Liberty ID-FF Protocols and Schema Specification".Version 1.2, November 2003.http://www.projectliberty.org/specs
 
16
 
17
D. Shin, G. Ahn, and P. Shenoy. "Ensuring Information Assurance in Federated Identity Management". In Proceedings of IEEE Internatinal Performance Computing and Communications Conference (IPCCC '04)April 2004.
 
18
The Globus Security Team. "Globus Toolkit Version 4 Grid Security Infrastructure:A Standards Perspective". Version 2, December 2004.
 
19
W3C. "Web Services Description Language (WSDL) 1.1". W3C Note, March 2001. http://www.w3.org/TR/wsdl
 
20
W3C. "The Platform for Privacy Preferences 1.0 (P3P1.0)Specification". W3C Recommendation, April 2002.http://www.w3.org/TR/P3P/
 
21
W3C. "SOAP Version 1.2 Part 0:Primer". W3C Recommendation, June 2003. http://www.w3.org/TR/soap12-part0/
 
22
 
23
V. Welch, I. Faster, C. Kesselman, O. Mulmo, L. Pearlman, S. Tuecke, J. Gawor, S. Meder, and F. Siebenlist. "X.509 Proxy Certificates for Dynamic Delegation". 3rd Annual PKI R&D Workshop 2004.
24


Collaborative Colleagues:
Hidehito Gomi: colleagues
Makoto Hatakeyama: colleagues
Shigeru Hosono: colleagues
Satoru Fujita: colleagues