• DocumentCode
    568520
  • Title

    Practicable Unified Security, Trust and Privacy (STP) Framework for Federated Access Management (FAM)

  • Author

    Ab Manan, Jamalul-lail ; Khattak, Zubair Ahmad ; Sulaiman, Suziah

  • Author_Institution
    Adv. Anal. & Modeling Cluster, MIMOS Berhad, Kuala Lumpur, Malaysia
  • fYear
    2012
  • fDate
    25-27 June 2012
  • Firstpage
    1411
  • Lastpage
    1416
  • Abstract
    In open environment there are always challenges in bridging the gap between Security, Trust and Privacy (STP) in Federated Access Management (FAM) systems. This challenge is mainly due to difficulties in providing a practical and efficient framework to handle the often conflicting requirements and expectations of STP in a unified manner. Many of the existing researches address the gap between mainly two areas i.e. security and privacy or security and trust. In this paper, we describe our efforts to narrow the STP gap in FAM and present some implementation experiences in crafting two distinct Unified STP Frameworks (UnifiedSTPFs), namely emergent and practicable, for federated access. We propose the use of the combined strengths of user authentication (AuthN), Trustworthy Mutual Attestation (TMutualA) protocol, and privacy enhancement via Shibboleth. We also presented some lessons learnt during implementation of the practicable UnifiedSTPF for FAM systems in Web Single Sign-On (WSSO) environment and possible future works.
  • Keywords
    Internet; authorisation; cryptographic protocols; data privacy; trusted computing; AuthN; FAM; Shibboleth; TMutualA protocol; UnifiedSTPF; WSSO environment; Web single sign-on environment; federated access management; practicable unified security trust and privacy framework; privacy enhancement; trustworthy mutual attestation protocol; unified STP frameworks; user authentication; Computer architecture; Conferences; High definition video; Privacy; Protocols; Security; Servers; architecture; federated access management; integrity measurement; mutual attestation; security; trust & privacy; trusted computing; trusted platform module;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Trust, Security and Privacy in Computing and Communications (TrustCom), 2012 IEEE 11th International Conference on
  • Conference_Location
    Liverpool
  • Print_ISBN
    978-1-4673-2172-3
  • Type

    conf

  • DOI
    10.1109/TrustCom.2012.222
  • Filename
    6296147