An Efficient Federated Identity Management Protocol For Heterogeneous Fog computing Architecture

Youcef Imine, A. Gallais, Y. Challal
{"title":"An Efficient Federated Identity Management Protocol For Heterogeneous Fog computing Architecture","authors":"Youcef Imine, A. Gallais, Y. Challal","doi":"10.23919/softcom55329.2022.9911414","DOIUrl":null,"url":null,"abstract":"With the emergence of new data externalization ar-chitectures, as fog computing, having access to external computing services will become much easier. Yet, these new architectures bring ahead many security concerns. Secure federated identity management (FidM) is a promising approach that facilitate fast and secure access to computing services. However, existing security mechanisms applied in the current FidM protocols does not efficiently support cross-collaboration in heterogeneous fog computing architecture where we have multiple security domains. In this paper, we propose a novel federated identity management protocol for secure identity mapping in heterogeneous fog computing architecture. Our protocol allows to create a federation among multiple heterogeneous security domains. Each domain is controlled by an autonomous authority that manages a set of service providers (fog nodes). The federation context is created in a completely decentralized manner. As a result, none of the authorities forming the federation will be in control of that context. Based on secure cryptographic token approach, our scheme allows any service provider to authenticate and map any end-user identity in the system. Regardless of where the token comes from, a service provider always uses the same key to verify the validity of that token. Moreover, the mapping process is fast and locally executed by the service provider. Finally, we present an evaluation of the performance of each phase in our protocol.","PeriodicalId":261625,"journal":{"name":"2022 International Conference on Software, Telecommunications and Computer Networks (SoftCOM)","volume":"2015 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-09-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 International Conference on Software, Telecommunications and Computer Networks (SoftCOM)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.23919/softcom55329.2022.9911414","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

With the emergence of new data externalization ar-chitectures, as fog computing, having access to external computing services will become much easier. Yet, these new architectures bring ahead many security concerns. Secure federated identity management (FidM) is a promising approach that facilitate fast and secure access to computing services. However, existing security mechanisms applied in the current FidM protocols does not efficiently support cross-collaboration in heterogeneous fog computing architecture where we have multiple security domains. In this paper, we propose a novel federated identity management protocol for secure identity mapping in heterogeneous fog computing architecture. Our protocol allows to create a federation among multiple heterogeneous security domains. Each domain is controlled by an autonomous authority that manages a set of service providers (fog nodes). The federation context is created in a completely decentralized manner. As a result, none of the authorities forming the federation will be in control of that context. Based on secure cryptographic token approach, our scheme allows any service provider to authenticate and map any end-user identity in the system. Regardless of where the token comes from, a service provider always uses the same key to verify the validity of that token. Moreover, the mapping process is fast and locally executed by the service provider. Finally, we present an evaluation of the performance of each phase in our protocol.
异构雾计算体系结构中一种高效的联邦身份管理协议
随着新的数据外部化架构(如雾计算)的出现,访问外部计算服务将变得更加容易。然而,这些新的体系结构带来了许多安全问题。安全联邦身份管理(FidM)是一种很有前途的方法,可以促进对计算服务的快速和安全访问。然而,当前FidM协议中应用的现有安全机制并不能有效地支持异构雾计算体系结构中的交叉协作,因为我们有多个安全域。本文针对异构雾计算架构下的安全身份映射问题,提出了一种新的联邦身份管理协议。我们的协议允许在多个异构安全域之间创建联邦。每个域由一个自治机构控制,该机构管理一组服务提供者(雾节点)。联邦上下文是以完全分散的方式创建的。因此,组建联邦的任何一个当局都无法控制这种情况。基于安全加密令牌方法,我们的方案允许任何服务提供者对系统中的任何最终用户身份进行身份验证和映射。无论令牌来自何处,服务提供者总是使用相同的密钥来验证该令牌的有效性。此外,映射过程是快速的,并且由服务提供者在本地执行。最后,我们对协议中每个阶段的性能进行了评估。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信