Federated identity-management protocols

  • Authors:
  • Birgit Pfitzmann

  • Affiliations:
  • IBM Zurich Research Lab

  • Venue:
  • Proceedings of the 11th international conference on Security Protocols
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

The question was, where have all the protocols gone? One answer, at least where authentication protocols might go, is what's called federated identity management protocols. This is a fairly vague term, and essentially I mean protocols like Microsoft Passport and the Liberty Alliance protocols. I have in the paper a complete protocol proposal which I think is better than those ones, called BBAE. You want to look at privacy, security, and access control points, and analyse these protocols, but they have quite a lot of limits. They contain useful things like operations security, browsers and passwords, and operating systems. And from the privacy point of view, you can actually have very good privacy with them for the typical case where there's no certification. If you want them together with the certifier, that can't be done without something that makes credentials, and as I said these sorts of problems raise analysis challenges.