DocumentCode :
2693609
Title :
Combining identity federation with Payment: The SAML-based Payment Protocol
Author :
Lutz, David J. ; Stiller, Burkhard
Author_Institution :
Univ. of Stuttgart, Stuttgart, Germany
fYear :
2010
fDate :
19-23 April 2010
Firstpage :
495
Lastpage :
502
Abstract :
The management of services offered within identity federations comprises not only the traditional service elements but also those management requirements derived from the federation´s specification. However, since a discrepancy between the management needs related to payment and the capabilities offered by the federation´s protocols can be observed, this paper aims to provide a solution to bridge this gap. SAML is currently used in many identity federations as a language and protocol for transmitting critical data about a participant´s authentication and his/her attributes. Authorization based upon attributes often fulfils the requirements within a non-commercial context. However, whenever payment is required, federation partners have to establish a solution to handle it. Whilst commercial service providers may often use their already established payment solutions, for semi-commercial providers as well as for micropayments and niche-providers, a new approach may be required. Therefore, this paper proposes to use the identity federation language SAML to build such a new solution. Using the novel designed SAML Payment Assertion, SAML is able to handle all the payment-related processes without compromising security. These benefits provided by the protocol and the language would raise the interests for new service providers to join federations that are built upon SAML.
Keywords :
credit transactions; data privacy; protocols; SAML payment assertion; commercial service providers; identity federation; participant authentication; payment protocol; security assertion markup languange; semi-commercial providers; Authentication; Authorization; Bridges; Costs; Identity management systems; Informatics; Protocols; Security; Service oriented architecture; Technology management;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network Operations and Management Symposium (NOMS), 2010 IEEE
Conference_Location :
Osaka
ISSN :
1542-1201
Print_ISBN :
978-1-4244-5366-5
Electronic_ISBN :
1542-1201
Type :
conf
DOI :
10.1109/NOMS.2010.5488478
Filename :
5488478
Link To Document :
بازگشت