• DocumentCode
    2149104
  • Title

    User-Controlled Automated Identity Delegation

  • Author

    Hoellrigl, Thorsten ; Kühner, Holger ; Dinger, Jochen ; Hartenstein, Hannes

  • Author_Institution
    Steinbuch Centre for Comput. (SCC), Karlsruhe Inst. of Technol. (KIT), Karlsruhe, Germany
  • fYear
    2010
  • fDate
    25-29 Oct. 2010
  • Firstpage
    230
  • Lastpage
    233
  • Abstract
    The growing number of IT services in distributed systems increases the need to allow users to keep track of which personal data is retained by which service. User-centric federated identity management (FIM) tackles this goal by enabling users to approve each data dissemination between the providers of identity-related information, so-called identity providers (IdPs), and the consumers of this information, the service providers. To prevent a single IdP from gaining a comprehensive set of user information, user-centric FIM motivates the use of multiple IdPs even though this distribution of responsibilities might result in information redundancy and therefore raises consistency issues. User-centric FIM systems do not cope with information consistency sufficiently, mainly because these systems require that each dissemination of user attributes is manually approved by the user. We propose an approach, named User-Controlled Automated Identity Delegation, that allows a controlled data dissemination based on an automated user approval by introducing an additional party called Identity Delegate. The Identity Delegate is designed in consideration of the following central ideas: (i) user centricity - all data dissemination is still under user control, (ii) privacy - the delegate cannot read or gather personal data, (iii) efficiency - the effort to integrate and operate the delegate within an existing FIM system is kept low. We cover the experience made with an implementation based on Windows CardSpace.
  • Keywords
    data privacy; distributed processing; information dissemination; information services; user centred design; IT services; data dissemination control; data privacy; distributed system; identity providers; identity related information; information consistency; information redundancy; user centric federated identity management; user controlled automated identity delegation; Authorization; Cryptography; Joining processes; Manuals; Privacy; Prototypes;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and Service Management (CNSM), 2010 International Conference on
  • Conference_Location
    Niagara Falls, ON
  • Print_ISBN
    978-1-4244-8910-7
  • Electronic_ISBN
    978-1-4244-8908-4
  • Type

    conf

  • DOI
    10.1109/CNSM.2010.5691295
  • Filename
    5691295