• DocumentCode
    30038
  • Title

    A Survey of Payment Approaches for Identity Federations in Focus of the SAML Technology

  • Author

    Lutz, David J. ; Stiller, Burkhard

  • Author_Institution
    Comput. Center (RUS), Univ. of Stutttgart, Stutttgart, Germany
  • Volume
    15
  • Issue
    4
  • fYear
    2013
  • fDate
    Fourth Quarter 2013
  • Firstpage
    1979
  • Lastpage
    1999
  • Abstract
    Identity Federations are increasingly being used to establish convenient and secure attribute-based authentication and authorization systems. Whilst this process began mainly in the academic sector, it is assumed that over the next few years more and more commercial Service Providers will join Identity Federations in order to offer their services and products to federated customers. However, the introduction of commercial Service Providers demands a solution for payment, which has not been deployed during the early years of Identity Federations. Thus, Service Providers have to implement not only the federation application, but also additional payment solutions; a problem, by which the federation may appear unattractive for Service Providers, especially semi-commercial or those requiring micropayments. Even for large commercial providers entering a federation, the lack of payment support is a major disadvantage that may lead to either customer or profit loss. Thus, although a combination of electronic Payment solutions and Identity Federation approaches would provide several benefits to its participants, there has not been much investigation of such combinations. Therefore, this paper analyses electronic payment approaches as well as Identity Federation mechanisms and focuses on a solution to bridge these two aspects. Besides early stages of identity-based payments, final full integrated SAML-based payment approaches, which merge payments and Identity Federation into a powerful business solution, are also highlighted. However, since security is a major concern when focusing on payment solutions, several approaches have been investigated, including security and privacy evaluations, and, within this survey, only those solutions providing a sufficient level of security and privacy have been taken into consideration.
  • Keywords
    XML; finance; security of data; SAML technology; SAML-based payment approach; attribute-based authentication; commercial service providers; electronic payment approach; identity federation approach; identity-based payments; micropayments; Credit cards; Cryptography; Electronic payments; Identification; Servers; Electronic Payment Approaches; Identity Federations; Liberty Alliance; SAML-based Payments; Shibboleth;
  • fLanguage
    English
  • Journal_Title
    Communications Surveys & Tutorials, IEEE
  • Publisher
    ieee
  • ISSN
    1553-877X
  • Type

    jour

  • DOI
    10.1109/SURV.2013.032713.00098
  • Filename
    6506140