{"title":"Privacy-preserving user identity in Identity-as-a-Service","authors":"T. H. Vo, W. Fuhrmann, K. Fischer-Hellmann","doi":"10.1109/ICIN.2018.8401613","DOIUrl":null,"url":null,"abstract":"In Federated Identity Management, providers from different security domains exchange messages containing authentication and authorisation credentials of users. As a result, a user can use his Personal Identifiable Information (PII) from one or more Identity Providers to gain access to other sites. Disseminating PII over intermediaries also requires protecting PII from being misused and unauthorised access. Identity-as-a- Service (IDaaS) provides a federated identity for users to access multiple Cloud services on demand but may preserve user privacy. In this paper, we present a novel approach for preserving privacy in IDaaS by combining Purpose Based Access Control and Attribute-based Encryption with multi-authorities support. Our approach is suitable for sharing sensitive user information in a large distributed and heterogeneous environment.","PeriodicalId":103076,"journal":{"name":"2018 21st Conference on Innovation in Clouds, Internet and Networks and Workshops (ICIN)","volume":"32 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-02-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 21st Conference on Innovation in Clouds, Internet and Networks and Workshops (ICIN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICIN.2018.8401613","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6
Abstract
In Federated Identity Management, providers from different security domains exchange messages containing authentication and authorisation credentials of users. As a result, a user can use his Personal Identifiable Information (PII) from one or more Identity Providers to gain access to other sites. Disseminating PII over intermediaries also requires protecting PII from being misused and unauthorised access. Identity-as-a- Service (IDaaS) provides a federated identity for users to access multiple Cloud services on demand but may preserve user privacy. In this paper, we present a novel approach for preserving privacy in IDaaS by combining Purpose Based Access Control and Attribute-based Encryption with multi-authorities support. Our approach is suitable for sharing sensitive user information in a large distributed and heterogeneous environment.