DocumentCode :
3593410
Title :
OCCASIO: An operable concept for confidential and secure identity outsourcing
Author :
Kohler, Jennifer ; Hartenstein, Hannes
Author_Institution :
Inst. of Telematics, Karlsruhe Inst. of Technol. (KIT), Karlsruhe, Germany
fYear :
2013
Firstpage :
235
Lastpage :
243
Abstract :
While federated identity management separates service provisioning from identity provisioning, the identity provider is usually operated at the home organization of the identities. We address the challenge of outsourcing the entire identity provider with its user database to an untrusted external provider in a secure and privacy-preserving way. With this type of outsourcing, the home organization is no longer required to operate high availability infrastructure for access management. Instead, the home organization only needs to frequently attest that the identity data in the outsourced database is still up to date, a task that is much less demanding than providing access decisions whenever a user wants to make use of a service. In this paper we present Occasio, a concept that permits secure outsourcing of identity and access management to untrusted external providers. Occasio builds on concepts of outsourcing databases and particularly on Merkle Hash Trees. We show that Occasio matches all security requirements for operation in an untrusted environment. Furthermore, we demonstrate that Occasio can be easily integrated into the SAML standard. We present results of a performance evaluation that shows that Occasio behaves well in terms of overhead. Finally, we show that with Occasio identity data of different home organizations can be `aggregated´ without being linkable by someone other than the services that are granted to do so by the user.
Keywords :
cloud computing; organisational aspects; outsourcing; security of data; tree data structures; Merkle hash trees; OCCASIO; SAML standard; federated identity management; high availability infrastructure; home organization; identity provider; identity provisioning; operable concept for confidential and secure identity outsourcing; outsourced database; secure outsourcing; service provisioning; Authorization; Availability; Organizations; Outsourcing; Protocols; Public key; Standards organizations; availability; cloud; identity and access management; service outsourcing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Integrated Network Management (IM 2013), 2013 IFIP/IEEE International Symposium on
Print_ISBN :
978-1-4673-5229-1
Type :
conf
Filename :
6572991
Link To Document :
بازگشت