Connecting Self-Sovereign Identity with Federated and User-centric Identities via SAML Integration

Hakan Yildiz, Christoph Ritter, Lan Thao Nguyen, Berit Frech, Maria Mora Martinez, Axel Küpper
{"title":"Connecting Self-Sovereign Identity with Federated and User-centric Identities via SAML Integration","authors":"Hakan Yildiz, Christoph Ritter, Lan Thao Nguyen, Berit Frech, Maria Mora Martinez, Axel Küpper","doi":"10.1109/ISCC53001.2021.9631453","DOIUrl":null,"url":null,"abstract":"Self-sovereign identity provides a feasible alternative to login via username and password through an identity provider to access digital services. It allows identity subjects to control and own their data. Although this is an appealing approach, it requires a whole new infrastructure with almost no dependencies on the existing ones. We designed and implemented a solution that combines an existing federated identity access management solution with the new approach by enabling authentication via self-sovereign-identity-based credentials while the identity provider retains verification and communication with the service provider via Security Assertion Mark Up Language. Thanks to the standardized federated systems in the German higher education domain, the solution not only enables a smooth transition to self-sovereign identities but can also be easily transferred to other universities using the same federated identity framework.","PeriodicalId":270786,"journal":{"name":"2021 IEEE Symposium on Computers and Communications (ISCC)","volume":"16 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-09-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE Symposium on Computers and Communications (ISCC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISCC53001.2021.9631453","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10

Abstract

Self-sovereign identity provides a feasible alternative to login via username and password through an identity provider to access digital services. It allows identity subjects to control and own their data. Although this is an appealing approach, it requires a whole new infrastructure with almost no dependencies on the existing ones. We designed and implemented a solution that combines an existing federated identity access management solution with the new approach by enabling authentication via self-sovereign-identity-based credentials while the identity provider retains verification and communication with the service provider via Security Assertion Mark Up Language. Thanks to the standardized federated systems in the German higher education domain, the solution not only enables a smooth transition to self-sovereign identities but can also be easily transferred to other universities using the same federated identity framework.
通过SAML集成将自主身份与联邦和以用户为中心的身份连接起来
自我主权身份提供了通过身份提供者通过用户名和密码登录访问数字服务的可行替代方案。它允许身份主体控制和拥有自己的数据。尽管这是一种吸引人的方法,但它需要一个全新的基础设施,几乎不依赖于现有的基础设施。我们设计并实现了一个解决方案,该解决方案将现有的联邦身份访问管理解决方案与新方法结合起来,通过基于自我主权身份的凭据进行身份验证,同时身份提供者通过安全断言标记语言保留验证和与服务提供者的通信。由于德国高等教育领域的标准化联邦系统,该解决方案不仅能够顺利过渡到自主身份,而且还可以使用相同的联邦身份框架轻松地转移到其他大学。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信