User-Centric Identity Management in Heterogeneous Federations | IEEE Conference Publication | IEEE Xplore

User-Centric Identity Management in Heterogeneous Federations


Abstract:

Over the past years Web applications increased in number and complexity (driven by ldquoWeb 2.0rdquo paradigm). Users need to manage different passwords to authenticate a...Show More

Abstract:

Over the past years Web applications increased in number and complexity (driven by ldquoWeb 2.0rdquo paradigm). Users need to manage different passwords to authenticate at these applications. Modern Web-based single sign-on solutions that reduce the complexity for usage and management of the userspsila credentials can be categorized in federated (typically SAML) or user-centric identity management (e.g., OpenID). On the one hand federated identity management is secure and most prevalent (especially in scientific communities). On the other hand user-centric approaches offer better usability and maintainability. While establishing federated identities for the Max Planck Society using the SAML-based Shibboleth system several extensions have been made to support the integration in different federations and allowing various authentication mechanisms being used by the 80 autonomous institutes. This paper describes the extensions by introducing an ldquoIdP Proxyrdquo that combines advantages of both federated and user-centric identity management functions.
Date of Conference: 24-28 May 2009
Date Added to IEEE Xplore: 12 June 2009
ISBN Information:
Conference Location: Venice/Mestre, Italy

I. Introduction

The increasing amount of web applications is one of the most important reasons why users have to remember different passwords to authenticate themselves. As web applications get more complex and offer possibilities that traditionally belonged to desktop applications (e.g., “Web 2.0” applications), the need for different passwords to authenticate is furthermore amplified.

Contact IEEE to Subscribe

References

References is not available for this document.