DocumentCode :
3223251
Title :
Service token for identity access management
Author :
Liu, WeiYi ; Tan, Yue ; Zhang, Enwei
Author_Institution :
Tsinghua Univ., Beijing, China
fYear :
2009
fDate :
7-11 Dec. 2009
Firstpage :
34
Lastpage :
39
Abstract :
This paper proposes a new token structure for efficient handling of identity access management for online composite software services. With the requirement of ¿Single Sign-On (SSO)¿ for atomic services in a given composite service, this token structure binds service attributes, including workflow, providers, users, operator permission, and operation environment, together in its creation process. The token can be viewed as a deciphered string produced by IDP (identity provider) and consumed by SP (service provider). The concept of conference key distribution is also used to distribute the token and to secure the transportation procedure. Furthermore, the Security Assertion Markup Language (SAML) is adopted to support the exchange of authentication and authorization information between SPs and IDPs. Finally, we apply our service token concept to SourceID Liberty 2.0 (an open source implementation for Liberty Alliance Project) as an illustration of its feasibility and practicability.
Keywords :
authorisation; cryptography; software architecture; Liberty Alliance Project; SourceID Liberty 2.0; atomic services; authentication information exchange; authorization information exchange; conference key distribution; deciphered string; identity access management; identity provider; online composite software service; operation environment; operator permission; security assertion markup language; service attributes; service oriented architecture; service provider; service token; single sign-on requirement; token structure; Authentication; Authorization; Character generation; Identity management systems; Information security; Markup languages; Permission; Public key cryptography; Service oriented architecture; Transportation; Access Control; Identity Management; Key Generation; Service; Service Token;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Services Computing Conference, 2009. APSCC 2009. IEEE Asia-Pacific
Conference_Location :
Singapore
Print_ISBN :
978-1-4244-5338-2
Electronic_ISBN :
978-1-4244-5336-8
Type :
conf
DOI :
10.1109/APSCC.2009.5394143
Filename :
5394143
Link To Document :
بازگشت