Security, trust and privacy (STP) framework for federated single sign-on environment

Zubair Ahmad Khattak, S. Sulaiman, J. Manan
{"title":"Security, trust and privacy (STP) framework for federated single sign-on environment","authors":"Zubair Ahmad Khattak, S. Sulaiman, J. Manan","doi":"10.1109/ICIMU.2011.6122770","DOIUrl":null,"url":null,"abstract":"Trust and privacy are hot and open concerns in Open Environment (OE). The Conventional Computing Platform (CCP) is deficient of platform trust that raises security concerns such as ‘phishing’ attacks. The Trusted Computing Group (TCG) took an initiative to tackle security and trust anxieties in OE via Trusted Platform Module (TPM) and Remote Attestation (RA). However, the current RA technique has its own limitation i.e. missing of Mutual Attestation (MA) and platform privacy fears in OE. The Federated Single Sign-on (FSSO) scheme such as Shibboleth allows its users to access a resource across domains in a privacy preserving manner but what is still missing; it is the mutual platform trust establishment among client and Identity Provider (IdP) platforms in OE. In this paper, we embrace MA technique and integrated in Shibboleth with UserName (UN) to guarantee user is a legitimate owner of UN but also his/her and home domain IdP platform mutually authenticated. Hence, we achieves (a) strong security with two factor authentication i.e. UN and mutual attestation, (b) mutual platform trust establishment between the client and IdP machines, and (c) resource access in privacy protecting manner. We practicality demonstrate unified STP Framework notion for FSSO environment by Testbed prototype implementation that confirms productivity and scalability of our approach.","PeriodicalId":102808,"journal":{"name":"ICIMU 2011 : Proceedings of the 5th international Conference on Information Technology & Multimedia","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"ICIMU 2011 : Proceedings of the 5th international Conference on Information Technology & Multimedia","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICIMU.2011.6122770","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

Abstract

Trust and privacy are hot and open concerns in Open Environment (OE). The Conventional Computing Platform (CCP) is deficient of platform trust that raises security concerns such as ‘phishing’ attacks. The Trusted Computing Group (TCG) took an initiative to tackle security and trust anxieties in OE via Trusted Platform Module (TPM) and Remote Attestation (RA). However, the current RA technique has its own limitation i.e. missing of Mutual Attestation (MA) and platform privacy fears in OE. The Federated Single Sign-on (FSSO) scheme such as Shibboleth allows its users to access a resource across domains in a privacy preserving manner but what is still missing; it is the mutual platform trust establishment among client and Identity Provider (IdP) platforms in OE. In this paper, we embrace MA technique and integrated in Shibboleth with UserName (UN) to guarantee user is a legitimate owner of UN but also his/her and home domain IdP platform mutually authenticated. Hence, we achieves (a) strong security with two factor authentication i.e. UN and mutual attestation, (b) mutual platform trust establishment between the client and IdP machines, and (c) resource access in privacy protecting manner. We practicality demonstrate unified STP Framework notion for FSSO environment by Testbed prototype implementation that confirms productivity and scalability of our approach.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
用于联邦单点登录环境的安全、信任和隐私(STP)框架
信任和隐私是开放环境(OE)中的热点和开放性问题。传统计算平台(CCP)缺乏平台信任,这引起了诸如“网络钓鱼”攻击等安全问题。可信计算组(TCG)通过可信平台模块(TPM)和远程认证(RA)主动解决OE中的安全和信任问题。然而,目前的RA技术有其自身的局限性,即在OE中缺少相互认证(MA)和平台隐私担忧。联邦单点登录(FSSO)方案,如Shibboleth允许其用户以保护隐私的方式跨域访问资源,但仍然缺少什么;它是OE中客户端与身份提供者(IdP)平台之间的相互平台信任的建立。本文采用了MA技术,并在Shibboleth中集成了UserName (UN),以保证用户是UN的合法所有者,并且他/她与主域IdP平台相互认证。因此,我们实现了(a)通过UN和相互认证两因素认证的强安全性,(b)在客户端和IdP机器之间建立相互的平台信任,(c)以隐私保护的方式访问资源。通过Testbed原型实现,验证了统一STP框架在FSSO环境下的可行性和可扩展性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
EWA: An exemplar-based watermarking attack Application of data mining techniques in customer realationship management for an automobile company An Augmented Reality's framework for mobile PAPR analysis of coded-OFDM system and mitigating its effect with clipping, SLM and PTS Analysing tasks through the sonification application and user intrepretation construction models
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1