Thaís Bardini Idalino, Marina Coelho, J. E. Martina
{"title":"Automated Issuance of Digital Certificates through the Use of Federations","authors":"Thaís Bardini Idalino, Marina Coelho, J. E. Martina","doi":"10.1109/ARES.2016.21","DOIUrl":null,"url":null,"abstract":"In recent years, there has been a trend for developing single sign-on systems. One alternative to deploy such systems is the use of Federated Identity Management systems. We argue that it is possible to use identity federations to automate the digital certificate issuance and use these certificates to authenticate back into federations. We use the data provided by the user's identity provider to build his certificate, reducing the costs of maintaining several registration authorities and simplifying the certificate issuance process. Making the process simpler to the users, we also encourage them to request and use their certificates. In special, the use of digital certificates for authentication can improve the usability and security of the authentication process. Furthermore, we present a prototype proving the feasibility of our proposal, as well as a discussion of the security and potential applications.","PeriodicalId":216417,"journal":{"name":"2016 11th International Conference on Availability, Reliability and Security (ARES)","volume":"4 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 11th International Conference on Availability, Reliability and Security (ARES)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ARES.2016.21","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
In recent years, there has been a trend for developing single sign-on systems. One alternative to deploy such systems is the use of Federated Identity Management systems. We argue that it is possible to use identity federations to automate the digital certificate issuance and use these certificates to authenticate back into federations. We use the data provided by the user's identity provider to build his certificate, reducing the costs of maintaining several registration authorities and simplifying the certificate issuance process. Making the process simpler to the users, we also encourage them to request and use their certificates. In special, the use of digital certificates for authentication can improve the usability and security of the authentication process. Furthermore, we present a prototype proving the feasibility of our proposal, as well as a discussion of the security and potential applications.