• DocumentCode
    2916639
  • Title

    Towards usable and reasonable Identity Management in heterogeneous IT infrastructures

  • Author

    Rieger, Sebastian ; Neumair, Bernhard

  • Author_Institution
    Gesellschaft fur wissenschaftliche Datenverarbeitung mbH, Gottingen
  • fYear
    2007
  • fDate
    May 21 2007-Yearly 25 2007
  • Firstpage
    560
  • Lastpage
    574
  • Abstract
    Identity management (IDM) has driven many IT projects especially in large IT infrastructures. Like other projects that focused on security or authentication, e.g. Public Key Infrastructures (PKI), they do not only reduce complexity and ease administration, but have to be managed themselves. This leads to costs and effort being necessary before gaining the benefit of unified authentication. This is maybe a reason why many projects dealing with IDM failed in the past or didn´t reach their initial goals. Nevertheless the trend to use decentralized access to resources e.g. via the Internet or World Wide Web seems unbroken - demanding for solutions to decentrally authenticate users. New techniques like Identity Federations address this requirement and extend Identity Management geographically. This paper shows ways to measure Identity Management efficiency and to enable balance between usability which influences the effort needed to authenticate and the resulting established security levels. This balance is defined as the key to reasonable and efficient Identity Management solutions in the future. Experience is gained from an Identity Management project to unify authentication in heterogeneous scientific IT infrastructures. The presented model and the lessons learned can be adopted for forthcoming Identity Management projects in other organizations or support decisions about future IDM projects. Beyond unveiling drawbacks of classical IDM solutions and showing solutions, the paper gives a concluding outlook on future IDM developments and upcoming challenges for authentication and security or access management.
  • Keywords
    Internet; authorisation; identification; message authentication; public key cryptography; Internet; World Wide Web; access management; authentication; decentralized access; heterogeneous IT infrastructures; identity federations; identity management; public key infrastructures; Authentication; Computer security; Costs; Hospitals; Identity management systems; Information security; Postal services; Project management; Usability; Web sites; Access Management; Authentication; Computer Security; Identity Federations; Identity Management; Security Management; Single Password; Single Sign-On;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Integrated Network Management, 2007. IM '07. 10th IFIP/IEEE International Symposium on
  • Conference_Location
    Munich
  • Print_ISBN
    1-4244-0798-2
  • Electronic_ISBN
    1-4244-0799-0
  • Type

    conf

  • DOI
    10.1109/INM.2007.374820
  • Filename
    4258572