Title :
The Trusted Attribute Aggregation Service (TAAS) - Providing an Attribute Aggregation Layer for Federated Identity Management
Author :
Chadwick, David W. ; Inman, George
Author_Institution :
Sch. of Comput., Univ. of Kent, Canterbury, UK
Abstract :
We describe a web based federated identity management system loosely based on the user centric Windows Card Space model. Unlike Card Space that relies on a fat desktop client (the identity selector) in which the user can only select a single card per session, our model uses a standard web browser with a simple plugin that connects to a trusted attribute aggregation web service (TAAS). TAAS supports the aggregation of attributes from multiple identity providers (IdPs) and allows the user to select multiple single attribute "cards" in a session, which more accurately reflects real life in which users may present several plastic cards and self-asserted attributes in a single session. Privacy protection, user consent, and ease of use are critical success factors. Consequently TAAS does not know who the user is, the user consents by selecting the attributes she wants to release, and she only needs to authenticate to a single IdP even though attributes may be aggregated from multiple IdPs. The system does not limit the authentication mechanisms that can be used, and it protects the user from phishing attacks by malicious SPs.
Keywords :
Web services; client-server systems; computer crime; data privacy; message authentication; online front-ends; trusted computing; TAAS; Web based federated identity management system; Windows card space model; attribute aggregation layer; authentication mechanisms; critical success factors; desktop client; identity selector; malicious SP; multiple identity providers; multiple single attribute; phishing attacks; plastic cards; plugin; privacy protection; self-asserted attributes; standard Web browser; trusted attribute aggregation Web service; trusted attribute aggregation service; user consent; Authentication; Authorization; Browsers; Cryptography; Protocols; Standards; attribute aggregation; identity management;
Conference_Titel :
Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
Conference_Location :
Regensburg
DOI :
10.1109/ARES.2013.38