• DocumentCode
    2588740
  • Title

    Scalable, Privacy-Preserving Remote Attestation in and through Federated Identity Management Frameworks

  • Author

    Ali, Tamleek ; Nauman, Mohammad ; Amin, Muhammad ; Alam, Masoom

  • Author_Institution
    Inst. of Manage. Sci., Peshawar, Pakistan
  • fYear
    2010
  • fDate
    21-23 April 2010
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Creating trustworthy online computing is an important open issue in security research. Trusted Computing aims to address this problem through the use of remote attestation but comes with its own baggage in the form of privacy concerns. Federated Identity Management Systems (FIDMSs), on the other hand, provide another form of trust but lack the ability to measure the integrity of platforms that they vouch for. We note that these two security architectures have reciprocal strengths and weaknesses and can be combined to create an architecture that addresses the concerns of both. In this paper, we propose an extended FIDMS in which the identity provider not only vouches for the identity of a user but also for her platform´s integrity. In this way, we (a) allow a service provider to establish trust on a client platform´s integrity without sacrificing privacy; and (b) create a feasible and scalable architecture for remote attestation. We describe our proposed architecture in the context of Shibboleth FIDMS and provide the details of the implementation of this system.
  • Keywords
    data integrity; data privacy; government data processing; Shibboleth FIDMS; federated identity management framework; privacy preserving remote attestation; security architectures; trustworthy online computing; Authentication; Authorization; Identity management systems; Information security; Information technology; Privacy; Resource management; Scalability; Service oriented architecture; Technology management;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Science and Applications (ICISA), 2010 International Conference on
  • Conference_Location
    Seoul
  • Print_ISBN
    978-1-4244-5941-4
  • Electronic_ISBN
    978-1-4244-5943-8
  • Type

    conf

  • DOI
    10.1109/ICISA.2010.5480294
  • Filename
    5480294