云环境下联邦身份管理系统中保护用户属性的隐私令牌技术

M. Abur, S. Junaidu, A. Obiniyi, S. Abdullahi
{"title":"云环境下联邦身份管理系统中保护用户属性的隐私令牌技术","authors":"M. Abur, S. Junaidu, A. Obiniyi, S. Abdullahi","doi":"10.1109/NigeriaComputConf45974.2019.8949645","DOIUrl":null,"url":null,"abstract":"Once an individual employs the use of the Internet for accessing information; carrying out transactions and sharing of data on the Cloud, they are connected to diverse computers on the network. As such, security of such transmitted data is most threatened and then potentially creating privacy risks of users on the federated identity management system in the Cloud. Usually, User’s attributes or Personal Identifiable Information (PII) are needed to access Services on the Cloud from different Service Providers (SPs). Sometime these SPs may by themselves violate user’s privacy by the reuse of user’s attributes offered them for the release of services to the users without their consent and then carrying out activities that may appear malicious and then causing damage to the users. Similarly, it should be noted that sensitive user’s attributes (e.g. first name, email, address and the likes) are received in their original form by needed SPs in plaintext. As a result of these problems, user’s privacy is being violated. Since these SPs may reuse them or connive with other SPs to expose a user’s identity in the cloud environment. This research is motivated to provide a protective and novel approach that shall no longer release original user’s attributes to SPs but pseudonyms that shall prevent the SPs from violating user’s privacy through connivance to expose the user’s identity or other means. The paper introduces a conceptual framework for the proposed user’s attributes privacy protection in a federated identity management system for the cloud. On the proposed system, the use of pseudonymous technique also called Privacy Token (PT) is employed. The pseudonymous technique ensures users’ original attributes values are not sent directly to the SP but auto generated pseudo attributes values. The PT is composed of: Pseudo Attribute values, Timestamp and SP_ID. These composition of the PT makes it difficult for the User’s PII to be revealed and further preventing the SPs from being able to keep them or reuse them in the future without the user’s consent for any purpose. Another important feature of the PT is its ability to forestall collusion among several collaborating service providers. This is due to the fact that each SP receives pseudo values that have no direct link to the identity of the user. The prototype was implemented with Java programming language and its performance tested on CloudAnalyst simulation.","PeriodicalId":228657,"journal":{"name":"2019 2nd International Conference of the IEEE Nigeria Computer Chapter (NigeriaComputConf)","volume":"463 ","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Privacy Token Technique for Protecting User’s Attributes in a Federated Identity Management System for the Cloud Environment\",\"authors\":\"M. Abur, S. Junaidu, A. Obiniyi, S. Abdullahi\",\"doi\":\"10.1109/NigeriaComputConf45974.2019.8949645\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Once an individual employs the use of the Internet for accessing information; carrying out transactions and sharing of data on the Cloud, they are connected to diverse computers on the network. As such, security of such transmitted data is most threatened and then potentially creating privacy risks of users on the federated identity management system in the Cloud. Usually, User’s attributes or Personal Identifiable Information (PII) are needed to access Services on the Cloud from different Service Providers (SPs). Sometime these SPs may by themselves violate user’s privacy by the reuse of user’s attributes offered them for the release of services to the users without their consent and then carrying out activities that may appear malicious and then causing damage to the users. Similarly, it should be noted that sensitive user’s attributes (e.g. first name, email, address and the likes) are received in their original form by needed SPs in plaintext. As a result of these problems, user’s privacy is being violated. Since these SPs may reuse them or connive with other SPs to expose a user’s identity in the cloud environment. This research is motivated to provide a protective and novel approach that shall no longer release original user’s attributes to SPs but pseudonyms that shall prevent the SPs from violating user’s privacy through connivance to expose the user’s identity or other means. The paper introduces a conceptual framework for the proposed user’s attributes privacy protection in a federated identity management system for the cloud. On the proposed system, the use of pseudonymous technique also called Privacy Token (PT) is employed. The pseudonymous technique ensures users’ original attributes values are not sent directly to the SP but auto generated pseudo attributes values. The PT is composed of: Pseudo Attribute values, Timestamp and SP_ID. These composition of the PT makes it difficult for the User’s PII to be revealed and further preventing the SPs from being able to keep them or reuse them in the future without the user’s consent for any purpose. Another important feature of the PT is its ability to forestall collusion among several collaborating service providers. This is due to the fact that each SP receives pseudo values that have no direct link to the identity of the user. The prototype was implemented with Java programming language and its performance tested on CloudAnalyst simulation.\",\"PeriodicalId\":228657,\"journal\":{\"name\":\"2019 2nd International Conference of the IEEE Nigeria Computer Chapter (NigeriaComputConf)\",\"volume\":\"463 \",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-10-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2019 2nd International Conference of the IEEE Nigeria Computer Chapter (NigeriaComputConf)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/NigeriaComputConf45974.2019.8949645\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 2nd International Conference of the IEEE Nigeria Computer Chapter (NigeriaComputConf)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/NigeriaComputConf45974.2019.8949645","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

一旦个人使用互联网获取信息;在云上进行交易和数据共享,它们连接到网络上的各种计算机。因此,这种传输数据的安全性受到最大威胁,然后可能会给云中的联邦身份管理系统上的用户带来隐私风险。通常,访问来自不同服务提供商(sp)的云服务需要用户的属性或个人身份信息(PII)。有时,这些服务提供商本身就可能侵犯用户的隐私,在未经用户同意的情况下,重用提供给他们的用户属性,向用户发布服务,然后进行可能具有恶意的活动,从而对用户造成损害。同样,应该注意的是,敏感用户的属性(例如姓名、电子邮件、地址和喜欢)是由所需的明文服务提供商以原始形式接收的。由于这些问题,用户的隐私正在受到侵犯。因为这些服务提供商可以重用它们或与其他服务提供商合作,在云环境中公开用户的身份。本研究的动机是提供一种保护性和新颖的方法,不再向服务提供商释放原始用户的属性,而是提供假名,以防止服务提供商通过纵容暴露用户身份或其他方式侵犯用户隐私。本文介绍了一个云联合身份管理系统中用户属性隐私保护的概念框架。在提出的系统中,使用了匿名技术,也称为隐私令牌(PT)。假名技术确保用户的原始属性值不会直接发送给SP,而是自动生成伪属性值。PT由以下三部分组成:Pseudo Attribute值、Timestamp和SP_ID。这些个人身份信息的构成使得用户的个人身份信息难以被披露,并进一步防止服务提供商在未经用户同意的情况下保留或将来出于任何目的重新使用这些信息。PT的另一个重要特征是它能够防止几个合作服务提供商之间的勾结。这是因为每个SP接收到的伪值与用户的身份没有直接联系。用Java编程语言实现了原型,并在CloudAnalyst仿真平台上进行了性能测试。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Privacy Token Technique for Protecting User’s Attributes in a Federated Identity Management System for the Cloud Environment
Once an individual employs the use of the Internet for accessing information; carrying out transactions and sharing of data on the Cloud, they are connected to diverse computers on the network. As such, security of such transmitted data is most threatened and then potentially creating privacy risks of users on the federated identity management system in the Cloud. Usually, User’s attributes or Personal Identifiable Information (PII) are needed to access Services on the Cloud from different Service Providers (SPs). Sometime these SPs may by themselves violate user’s privacy by the reuse of user’s attributes offered them for the release of services to the users without their consent and then carrying out activities that may appear malicious and then causing damage to the users. Similarly, it should be noted that sensitive user’s attributes (e.g. first name, email, address and the likes) are received in their original form by needed SPs in plaintext. As a result of these problems, user’s privacy is being violated. Since these SPs may reuse them or connive with other SPs to expose a user’s identity in the cloud environment. This research is motivated to provide a protective and novel approach that shall no longer release original user’s attributes to SPs but pseudonyms that shall prevent the SPs from violating user’s privacy through connivance to expose the user’s identity or other means. The paper introduces a conceptual framework for the proposed user’s attributes privacy protection in a federated identity management system for the cloud. On the proposed system, the use of pseudonymous technique also called Privacy Token (PT) is employed. The pseudonymous technique ensures users’ original attributes values are not sent directly to the SP but auto generated pseudo attributes values. The PT is composed of: Pseudo Attribute values, Timestamp and SP_ID. These composition of the PT makes it difficult for the User’s PII to be revealed and further preventing the SPs from being able to keep them or reuse them in the future without the user’s consent for any purpose. Another important feature of the PT is its ability to forestall collusion among several collaborating service providers. This is due to the fact that each SP receives pseudo values that have no direct link to the identity of the user. The prototype was implemented with Java programming language and its performance tested on CloudAnalyst simulation.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信