• DocumentCode
    1937441
  • Title

    Policy languages for digital identity management in federation systems

  • Author

    Bertino, Elisa ; Bhargav-Spantzel, Abhilasha ; Squicciarini, Anna Cinzia

  • Author_Institution
    CERIAS, Purdue Univ., West Lafayette, IN
  • fYear
    2006
  • fDate
    5-7 June 2006
  • Lastpage
    66
  • Abstract
    The goal of service provider federations is to support a controlled method by which distributed organizations can provide services to qualified individuals and manage their identity attributes at an inter-organizational level. In order to make access control decisions the history of activities should be accounted for, therefore it is necessary to record information on interactions among the federation entities. To achieve these goals we propose a comprehensive assertion language able to support description of static and dynamic properties of the federation system. The assertions are a powerful means to describe the behavior of the entities interacting in the federation, and to define policies controlling access to services and privacy policies. We also propose a log-based approach for capturing the history of activities within the federation implemented as a set of tables stored at databases at the various organizations in the federation. We illustrate how, by using different types of queries on such tables, security properties of the federation can be verified
  • Keywords
    authorisation; data privacy; distributed processing; formal languages; access control decisions; assertion language; digital identity management; distributed organizations; federation systems; log-based approach; policy languages; privacy policies; service provider federations; Access control; Authorization; Collaboration; Computer science; Databases; History; Identity management systems; Information security; Privacy; Protection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Policies for Distributed Systems and Networks, 2006. Policy 2006. Seventh IEEE International Workshop on
  • Conference_Location
    London, Ont.
  • Print_ISBN
    0-7695-2598-9
  • Type

    conf

  • DOI
    10.1109/POLICY.2006.22
  • Filename
    1631155