Shibboleth中面向隐私的属性交换扩展

Shoichirou Fujiwara, Takaaki Komura, Y. Okabe
{"title":"Shibboleth中面向隐私的属性交换扩展","authors":"Shoichirou Fujiwara, Takaaki Komura, Y. Okabe","doi":"10.1109/SAINT-W.2007.13","DOIUrl":null,"url":null,"abstract":"In frameworks for Web services like SAML, liberty or Shibboleth, a user can get authentication by asking one's IdP (identity provider) to issue a security assertion by which one can get access to services at an SP (service provider). If the SP additionally requests some attributes of one's, the user is forced to reveal the immediate values of them. There are cases where users must present detailed privacy information which SPs don't actually require to authorize them. We focus on Shibboleth and propose an extension of the attribute exchange protocol between an IdP and an SP in Shibboleth. While in the conventional framework of Shibboleth attributes are exchanged in immediate value, in our extension an SP requests an IdP to test whether user's attributes are satisfied some conditions, then the IdP returns either \"true\", \"false\" or \"unanswerable\" to the SP. We specify a language to describe the conditions as a query at the SP. We also extend an attribute authority at the IdP to evaluate the conditions presented from the SP","PeriodicalId":254195,"journal":{"name":"2007 International Symposium on Applications and the Internet Workshops","volume":"17 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2006-10-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"11","resultStr":"{\"title\":\"A Privacy Oriented Extension of Attribute Exchange in Shibboleth\",\"authors\":\"Shoichirou Fujiwara, Takaaki Komura, Y. Okabe\",\"doi\":\"10.1109/SAINT-W.2007.13\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In frameworks for Web services like SAML, liberty or Shibboleth, a user can get authentication by asking one's IdP (identity provider) to issue a security assertion by which one can get access to services at an SP (service provider). If the SP additionally requests some attributes of one's, the user is forced to reveal the immediate values of them. There are cases where users must present detailed privacy information which SPs don't actually require to authorize them. We focus on Shibboleth and propose an extension of the attribute exchange protocol between an IdP and an SP in Shibboleth. While in the conventional framework of Shibboleth attributes are exchanged in immediate value, in our extension an SP requests an IdP to test whether user's attributes are satisfied some conditions, then the IdP returns either \\\"true\\\", \\\"false\\\" or \\\"unanswerable\\\" to the SP. We specify a language to describe the conditions as a query at the SP. We also extend an attribute authority at the IdP to evaluate the conditions presented from the SP\",\"PeriodicalId\":254195,\"journal\":{\"name\":\"2007 International Symposium on Applications and the Internet Workshops\",\"volume\":\"17 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2006-10-23\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"11\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2007 International Symposium on Applications and the Internet Workshops\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SAINT-W.2007.13\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2007 International Symposium on Applications and the Internet Workshops","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SAINT-W.2007.13","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 11

摘要

在SAML、liberty或Shibboleth等Web服务框架中,用户可以通过请求自己的IdP(身份提供者)发出安全断言来获得身份验证,通过该断言,用户可以访问SP(服务提供者)的服务。如果SP额外请求用户的某些属性,用户将被迫显示这些属性的直接值。有些情况下,用户必须提供详细的隐私信息,而服务提供商实际上并不需要这些信息来授权他们。本文以Shibboleth为研究对象,提出了Shibboleth中IdP和SP之间的属性交换协议的扩展。在Shibboleth的传统框架中,属性以直接值交换,而在我们的扩展中,SP请求IdP来测试用户的属性是否满足某些条件,然后IdP向SP返回“真”、“假”或“不可回答”。我们指定了一种语言来描述这些条件作为SP的查询。我们还扩展了IdP的属性权限来评估SP提供的条件
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A Privacy Oriented Extension of Attribute Exchange in Shibboleth
In frameworks for Web services like SAML, liberty or Shibboleth, a user can get authentication by asking one's IdP (identity provider) to issue a security assertion by which one can get access to services at an SP (service provider). If the SP additionally requests some attributes of one's, the user is forced to reveal the immediate values of them. There are cases where users must present detailed privacy information which SPs don't actually require to authorize them. We focus on Shibboleth and propose an extension of the attribute exchange protocol between an IdP and an SP in Shibboleth. While in the conventional framework of Shibboleth attributes are exchanged in immediate value, in our extension an SP requests an IdP to test whether user's attributes are satisfied some conditions, then the IdP returns either "true", "false" or "unanswerable" to the SP. We specify a language to describe the conditions as a query at the SP. We also extend an attribute authority at the IdP to evaluate the conditions presented from the SP
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信