Sciweavers

DBSEC
2006

Notarized Federated Identity Management for Web Services

13 years 5 months ago
Notarized Federated Identity Management for Web Services
We propose a notarized federated identity management model that supports efficient user authentication when providers are unknown to each other. Our model introduces a notary service, owned by a trusted third-party, to dynamically notarize assertions generated by identity providers. An additional feature of our model is the avoidance of direct communications between identity providers and service providers, which provides improved privacy protection for users. We present an efficient implementation of our notarized federated identity management model based on the Secure Transaction Management System (STMS). We also give a practical solution for mitigating aspects of the identity theft problem and discuss its use in our notarized federated identity management model. The unique feature of our cryptographic solution is that it enables one to proactively prevent the leaking of secret identity information.
Michael T. Goodrich, Roberto Tamassia, Danfeng Yao
Added 30 Oct 2010
Updated 30 Oct 2010
Type Conference
Year 2006
Where DBSEC
Authors Michael T. Goodrich, Roberto Tamassia, Danfeng Yao
Comments (0)