Criteria for Evaluating the Privacy Protection Level of Identity Management Services

Hyangjin Lee, Inkyoung Jeun, Hyuncheol Jung
{"title":"Criteria for Evaluating the Privacy Protection Level of Identity Management Services","authors":"Hyangjin Lee, Inkyoung Jeun, Hyuncheol Jung","doi":"10.1109/SECURWARE.2009.31","DOIUrl":null,"url":null,"abstract":"Identity Management is the one of web services that manages the digital identity and the personally identifiable information of the user who subscribed for various web services in Internet. It was developed to provide user with an easy way to use and manage various user's digital identities that were provided from each web service. If the user subscribes to an Identity Management service, the user can access the other web sites affiliated with the Identity Management service and use their web services by using the identity issued by the Identity Management service. And the user can manage the user's personally identifiable information distributed among various web sites in an integrated way through this service. However, if the identity provider, which provides this Identity Management service, discloses the user’s identity and personal identifiable information, identity theft can happen throughout the entire affiliated web sites. As a result, the privacy protection level of the Identity provider, that is, the level of protection for personally identifiable information, is the critical factor of successful Identity Management service. Therefore, Identity Provider should provide an easy way to the internal or external auditor of them for assessing the privacy protection level. This paper describes privacy threats for each identity life cycle, such as Identity provision, propagation, use and maintain, and destruction, and proposes the criteria that evaluate the privacy protection level provided by the Identity provider as a countermeasure against these threats. The internal or external auditor can use the criteria described in this paper, as a way of assessing the privacy protection level of Identity Provider","PeriodicalId":382947,"journal":{"name":"2009 Third International Conference on Emerging Security Information, Systems and Technologies","volume":"7 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-06-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"17","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 Third International Conference on Emerging Security Information, Systems and Technologies","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SECURWARE.2009.31","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 17

Abstract

Identity Management is the one of web services that manages the digital identity and the personally identifiable information of the user who subscribed for various web services in Internet. It was developed to provide user with an easy way to use and manage various user's digital identities that were provided from each web service. If the user subscribes to an Identity Management service, the user can access the other web sites affiliated with the Identity Management service and use their web services by using the identity issued by the Identity Management service. And the user can manage the user's personally identifiable information distributed among various web sites in an integrated way through this service. However, if the identity provider, which provides this Identity Management service, discloses the user’s identity and personal identifiable information, identity theft can happen throughout the entire affiliated web sites. As a result, the privacy protection level of the Identity provider, that is, the level of protection for personally identifiable information, is the critical factor of successful Identity Management service. Therefore, Identity Provider should provide an easy way to the internal or external auditor of them for assessing the privacy protection level. This paper describes privacy threats for each identity life cycle, such as Identity provision, propagation, use and maintain, and destruction, and proposes the criteria that evaluate the privacy protection level provided by the Identity provider as a countermeasure against these threats. The internal or external auditor can use the criteria described in this paper, as a way of assessing the privacy protection level of Identity Provider
身份管理服务隐私保护水平评价标准
身份管理是对在Internet上订阅各种web服务的用户的数字身份和个人身份信息进行管理的web服务之一。它的开发目的是为用户提供一种简单的方法来使用和管理每个web服务提供的各种用户数字身份。如果用户订阅了身份管理服务,则用户可以使用身份管理服务颁发的身份访问该身份管理服务附属的其他网站并使用其web服务。用户可以通过该服务对分布在各个网站上的用户个人身份信息进行综合管理。但是,如果提供此身份管理服务的身份提供者公开了用户的身份和个人身份信息,则整个附属网站都可能发生身份盗窃。因此,身份提供者的隐私保护水平,即对个人可识别信息的保护水平,是身份管理服务成功与否的关键因素。因此,Identity Provider应该为它们的内部或外部审计员提供一种简单的方法来评估隐私保护级别。本文描述了每个身份生命周期中的隐私威胁,如身份提供、传播、使用和维护以及销毁,并提出了评估身份提供者提供的隐私保护级别的标准,作为应对这些威胁的对策。内部或外部审计员可以使用本文中描述的标准来评估身份提供者的隐私保护水平
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信