• DocumentCode
    2926664
  • Title

    Security, trust and privacy (STP) framework for federated single sign-on environment

  • Author

    Khattak, Zubair Ahmad ; Sulaiman, Suziah ; Manan, Jamalul-lail Ab

  • Author_Institution
    Dept. of Comput. & Inf. Sci., Univ. Teknol. PETRONAS, Tronoh, Malaysia
  • fYear
    2011
  • fDate
    14-16 Nov. 2011
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Trust and privacy are hot and open concerns in Open Environment (OE). The Conventional Computing Platform (CCP) is deficient of platform trust that raises security concerns such as `phishing´ attacks. The Trusted Computing Group (TCG) took an initiative to tackle security and trust anxieties in OE via Trusted Platform Module (TPM) and Remote Attestation (RA). However, the current RA technique has its own limitation i.e. missing of Mutual Attestation (MA) and platform privacy fears in OE. The Federated Single Sign-on (FSSO) scheme such as Shibboleth allows its users to access a resource across domains in a privacy preserving manner but what is still missing; it is the mutual platform trust establishment among client and Identity Provider (IdP) platforms in OE. In this paper, we embrace MA technique and integrated in Shibboleth with UserName (UN) to guarantee user is a legitimate owner of UN but also his/her and home domain IdP platform mutually authenticated. Hence, we achieves (a) strong security with two factor authentication i.e. UN and mutual attestation, (b) mutual platform trust establishment between the client and IdP machines, and (c) resource access in privacy protecting manner. We practicality demonstrate unified STP Framework notion for FSSO environment by Testbed prototype implementation that confirms productivity and scalability of our approach.
  • Keywords
    data privacy; security of data; STP framework; conventional computing platform; federated single sign-on environment; identity provider platforms; mutual attestation technique; open environment; phishing attacks; platform privacy; remote attestation technique; security trust and privacy framework; testbed prototype; trusted computing group; trusted platform module; Authentication; Kernel; Linux; Privacy; Protocols; federated single sign-on; integrity measurement architecture; privacy; remote attestation; trust; trusted computing; trusted platform module;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Technology and Multimedia (ICIM), 2011 International Conference on
  • Conference_Location
    Kuala Lumpur
  • Print_ISBN
    978-1-4577-0988-3
  • Type

    conf

  • DOI
    10.1109/ICIMU.2011.6122770
  • Filename
    6122770