DocumentCode :
182022
Title :
Increasing the Resilience and Trustworthiness of OpenID Identity Providers for Future Networks and Services
Author :
Kreutz, Diego ; Feitosa, Eduardo ; Cunha, Hugo ; Niedermayer, Heiko ; Kinkelin, Holger
fYear :
2014
fDate :
8-12 Sept. 2014
Firstpage :
317
Lastpage :
324
Abstract :
We introduce a set of tools and techniques for increasing the resilience and trustworthiness of identity providers (IdPs) based on OpenID. To this purpose we propose an architecture of specialized components capable of fulfilling the essential requirements for ensuring high availability, integrity and higher confidentiality guarantees for sensitive data and operations. Additionally, we also discuss how trusted components (e.g., TPMs, smart cards) can be used to provide remote attestation on the client and server side, i.e., how to measure the trustworthiness of the system. The proposed solution outperforms related work in different aspects, such as countermeasures for solving different security issues, throughput, and by tolerating arbitrary faults without compromising the system operations. We evaluate the system behavior under different circumstances, such as continuous faults and attacks. Furthermore, the first performance evaluations show that the system is capable of supporting environments with thousands of users.
Keywords :
authorisation; computer crime; smart cards; software architecture; software fault tolerance; trusted computing; IdPs resilience; IdPs trustworthiness; OpenID identity providers; TPM; arbitrary faults; architecture; attacks; client-and-server side; confidentiality guarantees; continuous faults; future networks; future services; remote attestation; smart cards; specialized components; system behavior evaluation; system operations; system trustworthiness; trusted components; Authentication; Logic gates; Protocols; Reliability; Servers; Virtual machine monitors; Identity providers; OpenID; advanced persistent threats; large scale DDoS; resilience; security; system and protocol vulnerabilities; trustworthiness assessment;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Availability, Reliability and Security (ARES), 2014 Ninth International Conference on
Conference_Location :
Fribourg
Type :
conf
DOI :
10.1109/ARES.2014.49
Filename :
6980298
Link To Document :
بازگشت