增强基于信息卡的身份管理系统中的用户隐私

Waleed A. Alrodhan
{"title":"增强基于信息卡的身份管理系统中的用户隐私","authors":"Waleed A. Alrodhan","doi":"10.4156/IJEI.VOL2.ISSUE3.8","DOIUrl":null,"url":null,"abstract":"Information Card-based Identity Management (ICIM) is one of the most prominent user-centric schemes. In this paper we identify two security flaws in ICIM systems that may lead to a serious privacy violation. The first is the reliance on Internet user judgements of the authenticity of service providers, and the second is the reliance of the system on a single layer of authentication. We also propose a solution designed to address both flaws. The proposed solution enhances the privacy of ICIM systems by mitigating the risk of users being deceived by fake service providers. It also reduces the risk of an attacker impersonating a legitimate user to access services offered by one or more service providers, after having broken the only means employed to authenticate the user to identity provider. We also provide a security and performance analysis of the proposed solution. In this paper, CardSpace is used as an example of an ICIM system, and the modification is described in the context of this system.","PeriodicalId":223554,"journal":{"name":"International Journal of Engineering and Industries","volume":"20 4","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-09-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Enhancing User Privacy in Information Card-Based Identity Management Systems\",\"authors\":\"Waleed A. Alrodhan\",\"doi\":\"10.4156/IJEI.VOL2.ISSUE3.8\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Information Card-based Identity Management (ICIM) is one of the most prominent user-centric schemes. In this paper we identify two security flaws in ICIM systems that may lead to a serious privacy violation. The first is the reliance on Internet user judgements of the authenticity of service providers, and the second is the reliance of the system on a single layer of authentication. We also propose a solution designed to address both flaws. The proposed solution enhances the privacy of ICIM systems by mitigating the risk of users being deceived by fake service providers. It also reduces the risk of an attacker impersonating a legitimate user to access services offered by one or more service providers, after having broken the only means employed to authenticate the user to identity provider. We also provide a security and performance analysis of the proposed solution. In this paper, CardSpace is used as an example of an ICIM system, and the modification is described in the context of this system.\",\"PeriodicalId\":223554,\"journal\":{\"name\":\"International Journal of Engineering and Industries\",\"volume\":\"20 4\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2011-09-30\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"International Journal of Engineering and Industries\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.4156/IJEI.VOL2.ISSUE3.8\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Engineering and Industries","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4156/IJEI.VOL2.ISSUE3.8","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

基于信息卡的身份管理(ICIM)是最突出的以用户为中心的身份管理方案之一。在本文中,我们确定了ICIM系统中可能导致严重隐私侵犯的两个安全漏洞。第一种是依赖互联网用户对服务提供商真实性的判断,第二种是系统对单层认证的依赖。我们还提出了一个旨在解决这两个缺陷的解决方案。提出的解决方案通过降低用户被虚假服务提供商欺骗的风险来增强ICIM系统的隐私性。它还降低了攻击者冒充合法用户访问由一个或多个服务提供者提供的服务的风险,在破坏了用于对用户进行身份验证的唯一方法之后。我们还对所建议的解决方案进行了安全性和性能分析。本文以CardSpace作为ICIM系统的一个实例,并在该系统的背景下描述了对该系统的修改。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Enhancing User Privacy in Information Card-Based Identity Management Systems
Information Card-based Identity Management (ICIM) is one of the most prominent user-centric schemes. In this paper we identify two security flaws in ICIM systems that may lead to a serious privacy violation. The first is the reliance on Internet user judgements of the authenticity of service providers, and the second is the reliance of the system on a single layer of authentication. We also propose a solution designed to address both flaws. The proposed solution enhances the privacy of ICIM systems by mitigating the risk of users being deceived by fake service providers. It also reduces the risk of an attacker impersonating a legitimate user to access services offered by one or more service providers, after having broken the only means employed to authenticate the user to identity provider. We also provide a security and performance analysis of the proposed solution. In this paper, CardSpace is used as an example of an ICIM system, and the modification is described in the context of this system.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信