Abstract
We propose a notarized federated identity management model that supports efficient user authentication when providers are unknown to each other. Our model introduces a notary service, owned by a trusted third-party, to dynamically notarize assertions generated by identity providers. An additional feature of our model is the avoidance of direct communications between identity providers and service providers, which provides improved privacy protection for users. We present an efficient implementation of our notarized federated identity management model based on the Secure Transaction Management System (STMS). We also give a practical solution for mitigating aspects of the identity theft problem and discuss its use in our notarized federated identity management model. The unique feature of our cryptographic solution is that it enables one to proactively prevent the leaking of secret identity information. © IFIP International Federation for Information Processing 2006.
Cite
CITATION STYLE
Goodrich, M. T., Tamassia, R., & Yao, D. (2006). Notarized federated identity management for web services. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 4127 LNCS, pp. 133–147). Springer Verlag. https://doi.org/10.1007/11805588_10
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.