Title :
Enhancing Claim-Based Identity Management by Adding a Credibility Level to the Notion of Claims
Author :
Thomas, Ivonne ; Meinel, Christoph
Author_Institution :
Hasso-Plattner-Inst., Potsdam, Germany
Abstract :
Claim based identity management denotes an open identity model which uses the notion of claims to describe identity attributes. A claim is an identity attribute named with an abstract identifier (e.g. a URI), which applications and services can use to specify the attributes they need. Open and extensible formats for the exchange of identity attributes ensure interoperability among different identity systems. For this reason, claim based identity management lays the ground for Identity metasystems, which provide an identity layer on top of existing identity systems and promise an easier management of digital identities among the Internet.However, the Internet grew into an environment of mostly isolated domains for a good reason. Service providers find it hard to accept identity information from any other than the own domain. While claim based identity management provides the means to specify identity information on a per attribute basis, trust is usually defined in a general manner. Service providers state the issuers of identity information, they trust, but do not restrict for what. In this paper, we argue that for a truly decentralized management of identity information, trust should be defined on the same granular level as identity information. We propose a model which considers trust on a per-claim basis. In our model, trust into a claim is defined as the assumed correctness and integrity of a claim in dependence of the issuer. As a proof-of-concept, we implemented a small flight booking scenario which uses claims augmented with an expected trust level to show how we can achieve more flexibility for the user in his choice of an identity provider when considering not only whom to trust, but for what.
Keywords :
Internet; data privacy; open systems; Internet; abstract identifier; claim based identity management enhancement; credibility level; decentralized management; digital identity; flight booking scenario; granular level; identity attribute description; identity information; interoperability; metasystem; open identity model; per attribute basis; service provider; Identity management systems; Identity Management; Identity Metasystem; Trust;
Conference_Titel :
Services Computing, 2009. SCC '09. IEEE International Conference on
Conference_Location :
Bangalore
Print_ISBN :
978-1-4244-5183-8
Electronic_ISBN :
978-0-7695-3811-2
DOI :
10.1109/SCC.2009.66