An Attribute Assurance Framework to Define and Match Trust in Identity Attributes

Ivonne Thomas, C. Meinel
{"title":"An Attribute Assurance Framework to Define and Match Trust in Identity Attributes","authors":"Ivonne Thomas, C. Meinel","doi":"10.1109/ICWS.2011.80","DOIUrl":null,"url":null,"abstract":"Identity federation denotes a concept for the controlled sharing of user authentication and user attributes between independent trust domains. Using WS-Federation, service providers and identity providers can set up a Circle of Trust, a so called federation, in which each member is willing to trust on assertions made by another partner. However, if a member has to rely on information received from a foreign source, the need for assurance that the information is correct is a natural requirement prior to using it. Identity assurance frameworks exist that can be used to assess the trustworthiness of identity providers. The result of this assessment is a level of trust, that can be assigned to an identity provider. However, existing approaches for evaluating identity assurance do not allow to define trust levels for individual attributes. In our trust model, we consider both: (a) trust in an identity provider as the issuer of assertions and (b) trust in single attributes that an identity provider manages. In this paper, we show how our approach that we implemented in a logic-based framework can be used in web service scenarios to provide trust information on the level of identity attributes, especially about the verification process, and to match trust requirements of attributes during request processing.","PeriodicalId":118512,"journal":{"name":"2011 IEEE International Conference on Web Services","volume":"6 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-07-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2011 IEEE International Conference on Web Services","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICWS.2011.80","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9

Abstract

Identity federation denotes a concept for the controlled sharing of user authentication and user attributes between independent trust domains. Using WS-Federation, service providers and identity providers can set up a Circle of Trust, a so called federation, in which each member is willing to trust on assertions made by another partner. However, if a member has to rely on information received from a foreign source, the need for assurance that the information is correct is a natural requirement prior to using it. Identity assurance frameworks exist that can be used to assess the trustworthiness of identity providers. The result of this assessment is a level of trust, that can be assigned to an identity provider. However, existing approaches for evaluating identity assurance do not allow to define trust levels for individual attributes. In our trust model, we consider both: (a) trust in an identity provider as the issuer of assertions and (b) trust in single attributes that an identity provider manages. In this paper, we show how our approach that we implemented in a logic-based framework can be used in web service scenarios to provide trust information on the level of identity attributes, especially about the verification process, and to match trust requirements of attributes during request processing.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
定义和匹配身份属性信任的属性保证框架
身份联合是一个概念,用于在独立的信任域之间受控地共享用户身份验证和用户属性。使用WS-Federation,服务提供者和身份提供者可以建立一个信任圈,即所谓的联合,其中每个成员都愿意信任另一个伙伴所做的断言。然而,如果一个成员必须依赖从外国来源获得的信息,那么在使用信息之前,需要确保信息是正确的,这是一个自然的要求。现有的身份保证框架可用于评估身份提供者的可信度。此评估的结果是一个信任级别,可以将其分配给身份提供者。但是,评估身份保证的现有方法不允许为单个属性定义信任级别。在我们的信任模型中,我们同时考虑:(a)对作为断言发布者的身份提供者的信任,以及(b)对身份提供者管理的单个属性的信任。在本文中,我们展示了我们在基于逻辑的框架中实现的方法如何在web服务场景中使用,以提供身份属性级别的信任信息,特别是关于验证过程的信息,并在请求处理期间匹配属性的信任需求。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Selection of Composable Web Services Driven by User Requirements Progressive Reliability Forecasting of Service-Oriented Software Opportunistic Composition of Sequentially-Connected Services in Mobile Computing Environments Improving Web API Discovery by Leveraging Social Information CLAM: Cross-Layer Management of Adaptation Decisions for Service-Based Applications
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1