DocumentCode :
2916639
Title :
Towards usable and reasonable Identity Management in heterogeneous IT infrastructures
Author :
Rieger, Sebastian ; Neumair, Bernhard
Author_Institution :
Gesellschaft fur wissenschaftliche Datenverarbeitung mbH, Gottingen
fYear :
2007
fDate :
May 21 2007-Yearly 25 2007
Firstpage :
560
Lastpage :
574
Abstract :
Identity management (IDM) has driven many IT projects especially in large IT infrastructures. Like other projects that focused on security or authentication, e.g. Public Key Infrastructures (PKI), they do not only reduce complexity and ease administration, but have to be managed themselves. This leads to costs and effort being necessary before gaining the benefit of unified authentication. This is maybe a reason why many projects dealing with IDM failed in the past or didn´t reach their initial goals. Nevertheless the trend to use decentralized access to resources e.g. via the Internet or World Wide Web seems unbroken - demanding for solutions to decentrally authenticate users. New techniques like Identity Federations address this requirement and extend Identity Management geographically. This paper shows ways to measure Identity Management efficiency and to enable balance between usability which influences the effort needed to authenticate and the resulting established security levels. This balance is defined as the key to reasonable and efficient Identity Management solutions in the future. Experience is gained from an Identity Management project to unify authentication in heterogeneous scientific IT infrastructures. The presented model and the lessons learned can be adopted for forthcoming Identity Management projects in other organizations or support decisions about future IDM projects. Beyond unveiling drawbacks of classical IDM solutions and showing solutions, the paper gives a concluding outlook on future IDM developments and upcoming challenges for authentication and security or access management.
Keywords :
Internet; authorisation; identification; message authentication; public key cryptography; Internet; World Wide Web; access management; authentication; decentralized access; heterogeneous IT infrastructures; identity federations; identity management; public key infrastructures; Authentication; Computer security; Costs; Hospitals; Identity management systems; Information security; Postal services; Project management; Usability; Web sites; Access Management; Authentication; Computer Security; Identity Federations; Identity Management; Security Management; Single Password; Single Sign-On;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Integrated Network Management, 2007. IM '07. 10th IFIP/IEEE International Symposium on
Conference_Location :
Munich
Print_ISBN :
1-4244-0798-2
Electronic_ISBN :
1-4244-0799-0
Type :
conf
DOI :
10.1109/INM.2007.374820
Filename :
4258572
Link To Document :
بازگشت